Developers of the XRP Ledger have issued an emergency update, version xrpld 3.4.1, on September 25, 2026, to address critical vulnerabilities within the XRPL protocol. The most severe of these vulnerabilities involved an overflow error within the payment engine. If exploited, this flaw could have allowed the creation of spendable XRP exceeding the total supply with just a single verified transaction.
Potential Impact and Mechanism of the Flaw
The identified vulnerability enabled an attacker to potentially generate XRP from nothing by utilizing uniquely crafted offers and a single payment transaction. The XRP created in this manner could be maintained in regular accounts, transferred to other wallets, exchanged in transactions, or sent to exchanges.
The issue occurred where the payment engine aggregated amounts during a single payment that consumed multiple offers from the order book. XRP balances are stored as integers with a fixed upper limit. When this limit was surpassed, the system didn’t throw an error but instead reset to a lower number. Consequently, the engine paid all offerors their full dues individually, collecting only the post-overflow reduced total from the recipient. The difference, contrary to the rules, constituted new XRP that should not have existed.
XRPL developers stressed that if exploited, this flaw could have generated spendable XRP exceeding the total supply within a single verified transaction.
Why the Security Check Failed
The XRP Ledger features a built-in security mechanism that ensures no transactions generate new XRP. However, since the total balance change was similarly subject to overflow, this mechanism failed to detect any discrepancies. Therefore, the vulnerability theoretically had the potential to bypass the network’s security validations.
Analysis revealed that this flaw had existed since the current payment engine was implemented in 2015. Nonetheless, the vulnerability was only discovered and reported last month.
Reporting Process and Urgent Fix
On September 22, 2026, a researcher reported that the integer overflow in the payment engine could be exploited to create XRP from nothing, via the XRPL Bug Bounty program. Consequently, a fix was promptly integrated into the xrpld 3.4.1 release.
The development team confirmed that no evidence of this flaw being exploited on any public network was found. Nevertheless, due to the magnitude of potential risk, the fix was released outside the usual change schedule.
Given the severity of the issue, the correction was deployed without following the standard change approval process. This marked the first deliberate intervention in transaction processing logic outside the established procedure since the change system was employed over a decade ago.
The fix becomes effective upon upgrading to version 3.4.1. Developers urge XRPL server operators to update to this latest version to maintain network synchronization.



