XRP Ledger Flaw Could Have Minted 18.45 Trillion Tokens, Patch Released

A security flaw found in the XRP Ledger on September 21, 2026, could have let an attacker create 18.45 trillion XRP in one transaction, more than 184 times the token's 100 billion supply. Developers patched the decade-old issue on September 25 and found no signs that it was exploited on public networks. Veria AI and researcher Cayden Liao were credited with the discovery, while a RippleX engineer warned that AI makes concealed security patches easier to reverse engineer.
The bug traced to code for calculating payments that was added in 2015. Veria AI spotted it on September 21, 2026, and it was submitted through the XRP Ledger bug bounty program the next day; researcher Cayden Liao was also credited.
The issue was a numeric overflow inside the payment-processing component when it handled many trading offers on the built-in exchange. An attacker could use hundreds of accounts offering tiny amounts of another token for large XRP payments, pushing the combined total past 64-bit limits. The system would then undercalculate, letting sellers receive full XRP while the buyer paid almost nothing. A patch, xrpld 3.4.1, arrived September 25 without public source code.
XRP holders, exchanges, and developers may feel the effects most. Had the flaw been exploited, markets could have faced sudden supply uncertainty, and exchanges might have struggled to distinguish legitimate tokens from improperly created ones. The emergency binary-only patch could also prompt open-source contributors to question transparency, while the AI warning may push blockchain teams to rethink how quickly hidden fixes can be reverse-engineered. These are possibilities, not observed outcomes, since no public-network exploitation was found.