XRP Ledger Discloses and Patches Bug That Could Have Broken Its Supply Cap
An integer-overflow flaw in the XRP Ledger payment engine could have created trillions of XRP beyond its 100 billion supply cap, and was patched before public
Key takeaways
- 18 trillion potential XRP. The flaw could have generated roughly 18 trillion XRP, 180 times the 100 billion supply cap.
- No exploitation detected. XRPL found no evidence the vulnerability was exploited on any public network.
- AI discovered the flaw. Veria Labs' AI system found the bug and earned a $250,000 maximum bounty.
What happened
On October 9, 2026, the XRP Ledger (XRPL) publicly disclosed an integer-overflow vulnerability in its payment engine that could have allowed attackers to create spendable XRP beyond the network's intended 100 billion token supply cap. The flaw was first reported on September 22, 2026, and patched in an emergency software update (xrpld 3.4.1) released three days later on September 25, 2026. RippleX confirmed no unauthorized XRP was created and no funds were lost in the incident.
The vulnerability was identified by Veria Labs' AI-powered security system, which analyzed rippled, the open-source software underpinning XRPL, and found two combined weaknesses that bypassed the network's monetary safeguards. One weakness was an integer overflow in the payment engine, where crafted trading offers could cause the system to miscalculate the amount a buyer owed, letting sellers receive full XRP payments while buyers were charged only a fraction of the actual amount. The second weakness affected the network's supply-protection mechanism, which relied on the same flawed arithmetic and failed to recognize newly created XRP.
According to XRPL, executing the exploit required an attacker to prepare hundreds of accounts and trading offers before submitting a single payment transaction, with only a few hundred XRP in largely refundable reserves and standard transaction fees needed. RippleX engineers independently reproduced the exploit and confirmed the newly generated XRP could be spent in subsequent transactions. Veria Labs received a $250,000 bug bounty, the maximum award for the program, for the discovery.
Why it matters
The vulnerability also highlighted gaps in existing security processes, as the underlying payment-engine code dated to 2015 and the affected supply safeguard was added in 2017, yet the combined flaw escaped more than a dozen security audits and contests with over $1 million in total bug bounty payouts since 2024, including a $550,000 prize pool competition.
Questions readers ask
Was the XRP Ledger bug exploited?
No, RippleX confirmed no unauthorized XRP was created and no evidence of exploitation was found on any public network.
How much XRP could the vulnerability have created?
The flaw could have generated roughly 18 trillion XRP, 180 times the network's intended 100 billion token supply cap.
Who discovered the XRP Ledger bug?
The vulnerability was identified by Veria Labs' AI-powered security system, which earned the maximum $250,000 bug bounty for the report.