Vulnerability
Published 2026-10-09
Verified 2026-10-11

XRP Ledger: integer overflow in the xrpld payment engine, present since 2015, could have minted spendable XRP beyond total supply in one transaction (rated critical by RippleX; fixed in emergency release 3.4.1, disclosed 9 October)

The XRP Ledger developers published a vulnerability disclosure report on 9 October 2026 for two bugs fixed in xrpld 3.4.1, the reference server for the XRP Ledger, which shipped as an emergency binary-only release on 25 September with source code published only at disclosure. The serious one is an integer overflow in the payment engine affecting xrpld 3.4.0 and earlier. When a single payment consumed many offers from the ledger's built-in order book, the engine summed what the buyer owed with plain 64-bit addition and no overflow check, so a large enough total wrapped around to a small number: each offer owner was paid in full while the buyer was charged only the wrapped total, creating new XRP. The invariant meant to confirm no transaction creates XRP used the same arithmetic and missed it. An attacker controlling all the accounts involved needed only a few hundred XRP in reserves plus fees, with hundreds of deliberately mispriced offers. Cayden Liao and Veria AI reported it through the XRPL bug bounty on 22 September; RippleX reproduced it, raised it from Major to critical, and says more than 80 per cent of default trusted-list validators ran 3.4.1 the day it shipped and that it found no evidence of exploitation on any public network. The second bug, a Batch inner-transaction wrapper validation gap (fixBatchV1_2) in 3.3.0 and 3.4.0, could have stalled ledger validation on a mixed-version network, but the Batch amendment was never active on Mainnet. No CVSS score was published. Primary: XRPL vulnerability disclosure report.

Product
xrpld (rippled), the XRP Ledger reference server
Versions
Payment engine overflow: xrpld 3.4.0 and earlier; Batch wrapper validation: 3.3.0 and 3.4.0
CVSS
Not published; RippleX rated the overflow critical
Exploited in Australia?
unknown
Patch to
Run xrpld 3.4.1 or later (now the minimum version expected on the network). Operators of exchanges, wallets and indexers that parse ledger data should also update XRPL SDKs if they handle Batch transactions.

Primary: XRPL.org — Vulnerability Disclosure Report for xrpld 3.4.1 (published 9 Oct 2026) · Vendor: XRPL.org — Introducing XRP Ledger version 3.4.1 (emergency release) · XRPLF/rippled releases on GitHub (3.4.1 source published with disclosure)

vulnerabilities