Newsroom
10 October, 2026 / News / AI / Tags: ripplex, xrp, vulnerability, emergency, ledger

RippleX has released xrpld 3.4.1 to close an integer-overflow flaw that could have allowed unauthorized creation of billions in XRP
The XRP Ledger has taken immediate steps to address a long-standing payment-engine vulnerability. Developers fixed the issue through an emergency software update that prevents potential miscalculations in how offers from the on-chain order book are processed.
The flaw existed in versions 3.4.0 and earlier. It stemmed from an unchecked 64-bit integer calculation during payments that consumed multiple offers. If the aggregated amount exceeded the maximum value, the result could wrap around unexpectedly. Sellers would still receive their full amounts, while the buyer paid only the wrapped figure, effectively creating new XRP.
An attacker could arrange hundreds of offers at precise prices before triggering a single payment to consume them all. This setup would require accounts holding large XRP reserves and paying fees, most of which could later be reclaimed. The problem dated back to the development of the current payment engine in 2015 and affected how the ledger handled order-book interactions on a large scale.
Ordinary payments could not trigger the vulnerability, limiting its use to carefully prepared scenarios. No public network has shown signs of exploitation so far.
RippleX released xrpld 3.4.1 on September 25. The update introduced overflow checks and a wider safety counter to stop any creation of spendable XRP. It went live without waiting for the normal amendment process, which would have required more than 80 percent validator support over two weeks.
More than 80 percent of the default Unique Node List validators were already running the patched version or a later release by the time the fix activated. A separate issue in the batch-transaction feature was also addressed in the same release, though that change only took effect on October 9 and did not impact the main network.
The patch spread rapidly across the network. Most trusted validators transitioned without delay, maintaining the ledger’s overall integrity. The emergency approach ensured the vulnerability could not remain active during any potential voting period.
Nodes running the updated software now enforce the new calculations, reducing the risk of similar arithmetic errors in future transactions. The ledger’s supply rules continue to govern all XRP, with no changes to total issuance or distribution protocols.
RippleX confirmed that the fix has been tested on standalone servers and aligns with the bug bounty program reporting process. The release also included safeguards for batch transactions, which were not active on the mainnet and posed no risk to user funds.
Validators and developers continue monitoring the network for any anomalies. The update restores full trust in the payment engine’s handling of complex order-book operations.









