XRP Ledger Deploys Emergency Fix for Critical Payment Engine Vulnerability

XRP Ledger developers released version xrpld 3.4.1 on September 25, 2026, to repair critical protocol flaws. The most serious issue was an integer overflow in the payment engine that could have let an attacker create spendable XRP beyond the total supply in a single validated transaction. The bug had been present since the payment engine's 2015 implementation and was reported on September 22, 2026.
Version xrpld 3.4.1 shipped on Sept. 25, 2026, after a Sept. 22 bug-bounty report. It fixed several protocol flaws, most seriously an integer overflow in the payment engine. Crafted offers plus one payment could make the ledger pay offer makers fully while charging the sender a smaller, wrapped sum.
Since the overall balance check overflowed too, the usual safeguard against creating XRP missed the mismatch. The vulnerable code dated to the 2015 payment engine. No public-network exploitation was found, but the fix bypassed normal change approval—reportedly the first such intervention in transaction logic in over a decade.
If exploited, this flaw could have shaken confidence in XRP's fixed-supply promise and in blockchain settlement more broadly. Holders, exchanges, and payment providers might have faced unexpected accounting or liquidity risks, while validators and server operators could see disruption if upgrades lag. The emergency patch may reinforce perceptions that coordinated disclosure and rapid fixes can contain severe protocol bugs, though it also highlights how long-lived code flaws can affect ordinary users and market trust.