A critical flaw in the XRP Ledger's payment engine, likely present since 2015, could have allowed an attacker to create unlimited new XRP, according to a disclosure report published by RippleX on October 9, 2026. The bug went undetected for about 11 years before being fixed.
The vulnerability was reported through the XRPL Bug Bounty programme on September 22, 2026 by Cayden Liao and Veria AI. It affected xrpld version 3.4.0 and earlier. RippleX confirmed the issue through its own testing and classified it as critical.
According to the report, the error stemmed from a miscalculation of payment amounts that allowed an internal counter to exceed its maximum limit, an integer overflow. A built-in security check that should have caught the problem failed to do so because it relied on the same flawed calculation mechanism.
How the exploit would have worked
To exploit the bug, an attacker would have needed to open several hundred accounts offering unusually high amounts of XRP in exchange for small amounts of other tokens. A single, specially prepared payment could then settle all of those offers at once, creating new XRP without providing equivalent value in return. RippleX developers demonstrated that XRP produced this way could actually be spent, confirming the flaw was not merely theoretical.
The developers said they found no evidence that attackers had actually exploited the bug before it was patched.
An emergency fix, and a broken rule
RippleX released version 3.4.1 on September 25, 2026 to close the vulnerability. The fix activated immediately upon installation, bypassing the network's usual voting procedure, under which more than 80 percent of trusted validators must support a change over a two-week period before it takes effect.
This marked the first time the voting procedure has been deliberately skipped since it was introduced more than ten years ago. RippleX said future changes will continue to go through the normal voting process, with exceptions reserved for especially severe security issues.
For a network that underpins XRP, one of the largest tokens by market value and widely held by European investors through exchanges and funds, the episode underscores how a decade-old coding error in core settlement logic can sit undiscovered until a bug bounty researcher finds it. The decision to override the ledger's consensus mechanism, even temporarily, also raises questions about the balance between decentralised governance and the need for rapid security responses on networks that process real financial value.



