# XRP Ledger Patches Flaw That Could Have Created XRP Beyond 100 Billion Supply

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/29386
Published: 2026-10-10T04:24:26.000Z
Updated: 2026-10-10T04:24:26.000Z
Section: Technology

> The vulnerability affected xrpld 3.4.0 and earlier and was fixed in version 3.4.1 after researchers reproduced the attack on a standalone server.

The XRP Ledger patched a payment-engine vulnerability that could have let attackers create and spend XRP beyond the network’s intended 100 billion-token supply.

The flaw affected xrpld 3.4.0 and earlier and was fixed in version 3.4.1, released Sept. 25. It was reported through the ledger’s bug-bounty program on Sept. 22 after researchers demonstrated the attack on a standalone server.

An attacker could have used hundreds of deliberately mispriced order-book offers in one payment. An integer overflow could cause sellers to receive large XRP credits while the buyer paid only a much smaller amount. The newly created XRP could then be distributed across hundreds of accounts and spent, traded or sent to exchanges.

RippleX reproduced the exploit and confirmed the unauthorized XRP could be used in a follow-up payment. The attack required a few hundred XRP for account and offer reserves, along with transaction fees; most reserves could later be recovered.

The ledger’s supply check used similarly vulnerable arithmetic, while spreading the balances across multiple accounts bypassed an account-level safeguard. More than 80% of validators on the default trusted validator list were running version 3.4.1 or later on Sept. 25. The flaw was likely present since the payment engine was written in 2015, and no evidence of public-network exploitation has been found.
