XRP Ledger discloses overflow bug that could have minted XRP beyond its supply cap

5 hours ago 1



The XRP Ledger has disclosed a critical bug that could have let an attacker create XRP out of thin air, beyond the network’s hard limit of 100 billion tokens. The flaw lived in xrpld versions 3.4.0 and earlier. It was patched quietly in September and made public on October 9, 2026. Investigators found no evidence it was ever used on a public network. How the bug worked The software used a 64-bit integer to add up XRP amounts when a single payment pulled from multiple offers on the order book. If that running total grew past the largest number the integer could hold, it wrapped around. The result was a number far smaller than reality. An attacker could exploit that gap to spend XRP that did not exist. The ledger’s books would look balanced, while the actual supply quietly ballooned. The existing safety checks did not catch it. When the inflated balances were scattered across many accounts, the system’s guardrails failed to flag the discrepancy. The cost of pulling this off was strikingly low. According to the disclosure, the exploit required specially crafted offers from hundreds of accounts, costing only a few hundred XRP in reserves and fees. Most of that outlay would have been re...

Read Entire Article