AdvertiseFee Deal Desk

XRP

RippleX Patches XRP Supply Bug That Could Have Minted Tokens Past the 100 Billion Cap

A critical XRP Ledger bug could have minted XRP beyond the 100 billion supply cap. RippleX fixed it in xrpld 3.4.1 and found no mainnet exploitation.

Be a creator
October 10, 2026, 06:58 AM UTC5 min read
AI SummaryAI
  • RippleX fixed an XRP Ledger payment-engine bug in xrpld 3.4.1 released September 25.
  • Researchers Cayden Liao and Veria AI reported the flaw via the XRPL bug bounty on September 22.
  • The integer-overflow bug could have minted XRP beyond the 100 billion supply cap in one transaction.
  • The flaw existed in the payment engine since its 2015 creation, the disclosure states.
bitget.com

A 2015 Flaw Against the 100 Billion Cap

A critical flaw in the XRP Ledger's payment engine could have let an attacker mint spendable XRP out of nothing, putting the token's fixed 100 billion supply at risk, but no evidence shows anyone ever used it. Researchers Cayden Liao and Veria AI reported the bug on September 22 through the XRPL bug bounty program, and the official disclosure published on Friday, October 9, traces the defect to the engine's creation in 2015. The XRP price near $1.41 around the disclosure put the full cap at roughly $88.8 billion, so the flaw threatened the value of the entire asset.

The defect sat in the engine that settles the blockchain's payments, the same rails that carry its PayFi traffic, and inside the built-in exchange where accounts list offers to trade one token for another. An attacker could stand up a few hundred accounts, each offering a trivial amount of some token in return for an enormous amount of XRP, then clear every offer with a single payment. The engine's running total grew past what its counter could hold and rolled back to a tiny value, much like an odometer passing its final digit, so sellers were paid in full while the buyer paid almost nothing and the difference entered the ledger as newly spendable XRP. A safety check built to catch minted supply read the same counter and missed the gap too. Only a payment clearing a large batch of offers in one stroke could reach the trigger, which explains why a defect of this age stayed hidden.

RippleX, Ripple's developer arm, reproduced the attack on local servers within days of the report, confirmed the counterfeit tokens could fund later payments, and rated the case critical. The official disclosure post states that a single verified transaction, funded by no more than a reserve of several hundred XRP plus fees, could have produced new tokens far beyond the entire circulating supply.

First Fix to Skip the Amendment Vote

Rule changes on the ledger normally travel through the amendment process, the mechanism that lets the network upgrade its rules without a hard fork. An amendment requires support from more than 80% of trusted validators, the servers that confirm ledger transactions, held for two weeks before it activates, a threshold meant to keep any small group from rewriting transaction rules on its own. This fix skipped that route entirely. RippleX shipped it in server software version 3.4.1 on Friday, September 25, three days after the report arrived, and it activated as each operator upgraded, the first transaction-processing change to deliberately bypass the amendment system since the mechanism was introduced more than ten years ago. Every release up to and including version 3.4.0 carried the defect.

Speed drove the decision. The server software is open source, so publishing the patch through a public vote would have shown attackers exactly where the bug sat and left it exploitable for the weeks a vote would take. The XRP Ledger Foundation, RippleX and validators instead chose to fix first and disclose later; more than 80% of default validators ran 3.4.1 or newer on release day, before the patched code was published. RippleX says voting remains the rule for future changes, and the team has added a step to its release procedure: every fixed finding, whether it comes from an audit or a bug bounty, must be reproduced against the original flaw on a release candidate before the fix counts as complete. A ledger running mixed versions risked disagreeing with itself on the outcome of a payment, a window the default validator set compressed to hours.

The disclosure landed one day after Cyber Capital founder Justin Bons called selling XRP as decentralized “fraud” in a public exchange with Ripple's David Schwartz. The episode hands that debate fresh evidence on both sides: the ledger's institutions did coordinate and the network upgraded within hours, yet the upgrade happened because a small set of parties set the consensus procedure aside.

No Exploitation on the Mainnet

No evidence points to an attack on the live network: RippleX states its review found no sign the overflow ever fired on the mainnet, and no party has come forward claiming to have minted tokens, so the record ends at an unproven threat rather than a realized loss. The residual risk named in the report is narrower: servers that upgraded late could briefly have disagreed with their peers on the outcome of the same payment, a window the default validator set closed on release day itself. In the wider XRP market context, our XRP technical analysis tracks price levels separately from this disclosure, earlier coverage shows how XRP Ledger payments activity slumped overnight, and readers weighing a first position can start with where to buy XRP.

COINOTAG's editorial and research desk.

AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.