XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
A decade-old bug in the XRP Ledger was patched that could have allowed attackers to create and spend new XRP tokens, violating the fixed supply of 100 billion XRP. The vulnerability exploited a counting error in the ledger’s built-in exchange, enabling attackers to receive large amounts of XRP while paying almost nothing. RippleX, Ripple’s developer arm, found no evidence of exploitation on public networks and fixed the flaw in the xrpld 3.4.1 software release on September 25, 2026.
Why it matters
This development matters because it exposed a severe risk to the integrity of XRP’s fixed supply, which is critical for institutions relying on the ledger. The flaw could have undermined confidence in the XRP market by allowing unlimited creation of new tokens and potential market manipulation. The source does not explain further impacts on policy or industry beyond this.
Key context
The XRP Ledger was launched in 2012 with a fixed supply of 100 billion XRP tokens. The bug dates back to 2015 and involved the ledger’s built-in token exchange and a counting error during transactions that allowed attackers to artificially generate XRP. The attack required only a few hundred XRP for account openings and could spread XRP payouts across hundreds of accounts to evade detection mechanisms. RippleX discovered the issue internally and deployed a silent fix in the ledger’s server software.
Key numbers and entities
RippleX, the developer arm of Ripple, identified and fixed the bug in xrpld 3.4.1 released on September 25, 2026. The XRP Ledger’s total fixed supply is 100 billion tokens. The bug dates from 2015. The researcher Cayden Liao and Veria AI reported the vulnerability on September 22, 2026.
What remains unclear
It remains unclear if any private or undisclosed networks experienced exploitation of the bug. The source does not specify how widespread or feasible the attack would have been under real-world conditions. Details on the exact nature of the counting error and its technical fix were not disclosed by developers.