10-Year-Old Bug Threatening XRP Supply Fixed

A Critical Flaw Hidden in Plain Sight
Imagine finding out that a major digital vault had a hidden back door for an entire decade. That is essentially what happened with the XRP Ledger, where a major flaw went unnoticed for years.
A security report released on October 9, 2026, revealed a serious bug in the XRP Ledger payment engine. If a hacker had found it, they could have created spendable XRP out of thin air, breaking the network's strict 100 billion token supply cap.
At a token price of roughly $1.41, the total supply of XRP represents an $88.8 billion market value. Fortunately, developer arm RippleX confirmed there is no evidence that anyone ever discovered or used the bug to create illegal tokens.
Please note: Past performance of digital assets does not guarantee future results. Crypto assets remain highly volatile and subject to market risk.
How the Payment Bug Worked
To understand the issue, it helps to look at how trades happen on the network. The XRP Ledger contains a built-in decentralized marketplace where users list offers to trade one token for another.
According to technical reports, an attacker could open a few hundred accounts. Each account would offer a tiny amount of a custom token in exchange for a massive amount of XRP.
The attacker would then execute a single payment designed to clear every offer at the same time. This triggered an integer overflow error in the software counter.
Much like an old car odometer rolling back to zero after hitting its limit, the total transaction counter grew too large and reset to a tiny number. The system paid the sellers in full, but charged the buyer almost nothing.
Because the ledger's built-in safety check relied on that exact same counter, the system completely missed the discrepancy.
Discovery and Emergency Patch
The flaw likely existed in the codebase since 2015. Security researcher Cayden Liao and Veria AI spotted the issue and submitted it through the XRPL Bug Bounty program on September 22, 2026.
The bug affected server software version xrpld 3.4.0 and earlier builds. Following the report, developers worked privately behind the scenes to secure the code before publicly disclosing the flaw.
Why Developers Skipped the Standard Public Vote
Under normal circumstances, changing rules on the XRP Ledger requires a two-week public amendment process. More than 80% of trusted network validators must approve the update during that timeframe.
This time, developers handled things differently. The fix was released in server software version 3.4.1 on September 25, 2026, taking effect as soon as node operators updated their software.
RippleX noted that this was the first time in over ten years that a processing change was deliberately implemented without waiting for an amendment vote.
The decision was made because a public vote would have exposed the vulnerability in open code for weeks while the network remained vulnerable to attacks. The XRPL Foundation, RippleX, and key validators agreed on the silent patch, and over 80% of default validators upgraded on release day before the fix was made public.
Decentralization Context and Governance
The timing of the disclosure coincides with ongoing discussions regarding XRP's governance. Just a day prior to the disclosure, CyberCYBER+1.98% Capital founder Justin Bons publicly questioned XRP's decentralization claims during a debate with RippleXRP+0.34% Chief Technology Officer David Schwartz.
While emergency updates protect user funds from critical exploits, they also trigger debates on how network changes should be coordinated.
RippleX emphasized that skipping the amendment vote was an exceptional step for a security emergency, and that standard community voting remains the operational rule for future protocol updates.
Latest blog posts

Lithuania Aligns Crypto User Tracking Rules With EU Framework
Lithuania's State Tax Inspectorate updated crypto user reporting rules under Order VA-63 to match broader European Union tax transparency standards.

Bitcoin's Volatility Drops, But Extreme Price Swings Rise
While Bitcoin's average volatility has plummeted in 2026, extreme single-day price jumps are occurring more frequently than in 2018, challenging traditional risk models.

Fake Relationship Scam Costs $211K: Courier Arrested
An Alabama sting operation stopped a crypto scam courier, but the victim's total losses continued to grow.