RippleX Patches Critical XRP Ledger Bug That Risked Supply Cap Breach
XRP Ledger developers revealed a decade-old bug that could have let attackers create spendable XRP and push the supply past its 100 billion cap. RippleX patched the issue in xrpld 3.4.1 on Sept. 25 and found no evidence of exploitation on public networks. The vulnerability stemmed from an integer overflow when processing many offers, and the fix was deployed outside the usual amendment process to avoid leaving the network exposed.
Cayden Liao and Veria AI reported the flaw through XRPL's bug bounty on Sept. 22. RippleX reproduced the attack on a standalone server, confirmed the created XRP could be spent later, and raised severity from major to critical.
The bug dated to the payment engine built in 2015. All 100 billion XRP were created at the ledger's 2012 launch, and transaction processing is not intended to mint additional tokens.
If such a flaw had been exploited, XRP holders, exchanges, and payment users could have faced dilution, market confidence shocks, and disputes over ledger balances. Validators and developers may bear pressure to coordinate emergency fixes, while businesses relying on XRP settlement might reassess operational risk. Because no exploitation was found and the patch deployed, immediate societal impact may be limited, though the episode could strengthen calls for audits and transparent disclosure.