Ripple Fixes XRP Minting Bug and Batch-Processing Consensus Risk
The xrpld 3.4.1 release fixed an integer-overflow flaw and a batch-transaction validation issue affecting earlier versions.

Ripple fixed two vulnerabilities in the XRP Ledger’s xrpld software, including a payment-engine flaw that could have created spendable XRP without authorization.
The critical issue affected version 3.4.0 and earlier. The payment engine summed amounts across multiple offers using a 64-bit integer without checking for overflow. If the total exceeded the limit, the value could wrap around, allowing offer makers to receive the full amount while buyers paid only the wrapped figure.
Exploiting the flaw required constructing hundreds of malicious offers and spending roughly hundreds of XRP in reserves and fees. Ordinary payments could not trigger the vulnerability, and no evidence of exploitation on public networks was identified. The fix became effective with the 3.4.1 release on Sept. 25 and did not require an amendment.
A separate validation problem affected versions 3.3.0 and 3.4.0. The XLS-56 batch-transaction feature required internal transactions to use a RawTransaction field, but servers did not enforce that requirement. The mismatch risked different node versions interpreting fields differently.
The fixBatchV1_2 amendment corrected the issue and activated on the mainnet Oct. 9. No fund losses or private-key exposure resulted from the batch-processing flaw.