Saturday, October 10, 2026
Industry / XRP Ledger

A bug believed to have sat in the XRP Ledger since 2015 could have minted XRP from nothing. It was patched with no sign anyone used it

Lines of code on a computer monitor. File photo. Photo: Markus Spiske / Wikimedia Commons (CC0)

The XRP Ledger carried a bug, apparently for more than a decade, that could have let an attacker create XRP out of nothing, its developers disclosed on Friday. A report on xrpl.org traces the flaw to the payment engine written in 2015, says it was fixed last month, and says there is no evidence it was exploited on any public network.

The problem was arithmetic. When a single payment bought up many offers on the ledger's built-in exchange, the software added up the XRP owed without checking whether the total had grown too large to count. A big enough total wrapped around to a small number. The sellers were paid in full, the buyer was charged only the small figure, and the difference was new XRP. The safety check meant to catch XRP being created relied on the same faulty sum.

An attacker would have needed a few hundred accounts, each offering a tiny amount of a token for a very large amount of XRP. The cost was a few hundred XRP in account reserves, which are returned, plus transaction fees, the report says.

Researcher Cayden Liao and Veria AI reported the bug on September 22. Engineers at RippleX, Ripple's developer arm, reproduced it and rated it critical. The fix went out in xrpld 3.4.1 on September 25 and took effect on each server as it upgraded. More than 80% of validators on the default list were running it that day.

XRP's supply is meant to be fixed at 100 billion, CoinDesk noted. Operators still on older software are told to upgrade.

This story is reporting and analysis. It is not financial, legal or tax advice.