XRP Ledger Developers Patch Critical Bug That Allowed Unlimited Token Minting
XRP Ledger (BITSTAMP:XRPUSD) developers released a vulnerability disclosure detailing an emergency software update, xrpld 3.4.1, designed to patch a critical flaw in the network payment engine. Originally reported through a bug bounty program on September 22, 2026, the integer overflow bug had been present in the code since 2015 and could have allowed a malicious actor to create unauthorized XRP tokens in a single transaction.
The flaw stemmed from how the ledger processed complex payments involving multiple order book offers. When transaction totals exceeded the maximum integer limit, calculations wrapped around to a tiny sum, charging the sender a fraction of the actual cost while crediting recipients in full. Built-in system safety checks also wrapped identically, masking the error. Developers confirmed that no public network exploits were detected before the emergency release on September 25, 2026.
To deploy the fix immediately, developers bypassed the traditional amendment voting process for the first time in over ten years. Server operators are urged to update to xrpld 3.4.1 right away to keep their systems secure and synchronized with the broader network. XRP traded around 1.402 USD, up 0.52% on the day.
Key points
- Developers patched a critical integer overflow bug in XRP Ledger server version xrpld 3.4.1.
- The flaw had existed since 2015 and could have allowed unauthorized creation of XRP tokens.
- Investigation confirmed there is no evidence that the security vulnerability was exploited on public networks.
- Developers bypassed the traditional amendment voting process to release the emergency patch immediately.
- Network server operators must upgrade to the latest software release to stay in sync with the ledger.
Written by our AI from expert market sources across the web. It can contain mistakes: check the facts before acting on them. Write-ups powered by the free AI API at FreeTheAI.org
How we writeDisclaimerQuestions and answers
Was any XRP illegally created using the security bug?
No. Developers reported no evidence that the payment engine overflow bug was ever exploited on any public network.
How was the XRP Ledger security bug fixed?
Developers released an emergency software update, xrpld 3.4.1, which bypassed the usual amendment process to apply immediate code fixes.
What should XRP Ledger node operators do now?
Server operators are advised to upgrade immediately to version xrpld 3.4.1 to maintain network synchronization and security.
