XRP Ledger reveals patched bug that could have exceeded token supply limit

The XRP Ledger disclosed a critical arithmetic flaw in xrpld versions 3.4.0 and earlier that could have allowed an attacker to create XRP beyond the 100 billion token cap. The bug was patched in an emergency release, xrpld 3.4.1, in September and made public on October 9, with no evidence it was exploited on a public network. It involved a 64-bit integer overflow when summing XRP amounts across multiple offers on the order book.
The defect affected xrpld 3.4.0 and older. It arose when a payment drew from several order-book offers and their XRP totals were summed in a 64-bit integer; an overflow could make the total appear smaller, allowing nonexistent tokens to be spent while records still balanced. Existing safeguards missed this when funds were spread among many accounts.
Researcher Cayden Liao reported it on Sept. 22, 2026, through the XRPL Bug Bounty program. RippleX reproduced the attack on a standalone server and confirmed the extra XRP was spendable. A patch, xrpld 3.4.1, shipped Sept. 25 without the usual validator vote. The flaw may have existed since the payment engine was built around 2015.
XRP holders, exchanges, and payment services could be affected if similar flaws erode confidence in the ledger’s fixed supply. Node operators may face pressure to upgrade quickly, since older software could carry known risks. The emergency patch, which bypassed the usual validator vote, may prompt broader discussion about how quickly critical fixes should be deployed and how much trust users place in core developers. For now, the absence of known exploitation may limit immediate market or social disruption.