# XRP Ledger Fixes Decade-Old Bug That Could Create XRP

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/29434
Published: 2026-10-10T07:45:19.000Z
Updated: 2026-10-10T07:45:19.000Z
Section: Technology

> The vulnerability in the payment engine was patched in xrpld 3.4.1 after researchers demonstrated unauthorized XRP creation in testing.

XRP Ledger fixed a roughly decade-old payment-engine vulnerability that could have allowed attackers to create spendable XRP without authorization, potentially exceeding the network’s total supply.

The flaw involved an unchecked 64-bit integer calculation when a payment consumed many offers from the on-chain order book. If the combined amount exceeded the maximum value, the calculation could wrap to a much smaller number while sellers still received the full amounts. The difference could become newly created XRP.

An attacker could have prepared hundreds of accounts with offers for very large amounts of XRP and then used another account to consume them in one payment. The vulnerability may have existed since 2015, when the current payment engine was developed.

The fix shipped with xrpld 3.4.1 on Sept. 25. It was applied without the network’s usual amendment vote, which normally requires more than 80% support from trusted validators for two consecutive weeks. The emergency approach was intended to prevent the vulnerability from remaining exposed during a public voting period.

No evidence indicates the flaw was exploited on a public network. The same release also addressed a separate issue in the batch-transaction feature, which was not active on the main network and did not affect user funds.
