MCAP $2.79T ▼ 2.56% 24H VOL $64.5B BTC.D 59.6% FEAR & GREED 64 Greed BTC FEE 3 sat/vB BTC $82,729 ▲ 0.26% ETH $2,492 ▼ 0.16% USDT $0.9992 ▼ 0.00% BNB $748.27 ▲ 0.90% XRP $1.40 ▲ 0.42% USDC $0.9997 ▲ 0.01% SOL $109.38 ▼ 0.56% TRX $0.3307 ▼ 0.38% FIGR_HELOC $1.00 ZEC $1,221 ▼ 0.38%

Altcoins

XRP Ledger patches 2015 bug that could have minted XRP

The XRP Ledger fixed a payment engine flaw that could have created spendable XRP, and says it found no evidence of exploitation.

CoinDesk AI Desk
· 4 min read
✓ 3 SOURCES CHECKED
XRP Ledger patches 2015 bug that could have minted XRP
Image: Coinpedia

Key takeaways

  1. Two flaws disclosed. XRPL disclosed two software vulnerabilities on October 9, 2026, including one it treated as critical.
  2. The cap held. All 100 billion XRP were created when the ledger launched in 2012.
  3. The patch came first. The fix shipped in xrpld version 3.4.1, released on September 25, before the October 9 disclosure.

What happened

The XRP Ledger disclosed two software vulnerabilities on October 9, 2026. The critical one sat in the payment engine that settles trades across the ledger's built-in exchange, and it could have let an attacker create spendable XRP. The flaw traces back to code written in 2015, according to the disclosure report. The patch shipped in xrpld version 3.4.1, released on September 25. XRPL Operations has since stated that it found no evidence the issue was exploited on any public network.

When a single payment consumed many offers, the engine added up the amounts using unchecked 64-bit arithmetic, so a large total wrapped around to a small one. Sellers were paid in full while the buyer was charged only the tiny wrapped total. The ledger's safety check, built to catch new XRP, used the same unchecked math and missed it. An attacker would have needed hundreds of deliberately mispriced offers and one payment routed through them, at a cost of a few hundred XRP in reserves plus ordinary transaction fees. Researcher Cayden Liao, working with Veria AI, reported the flaw to Ripple's developer team on Sept. 22, XRPL records the report through its bug bounty program on September 22, 2026.

A second, lower-severity bug involved how Batch transactions are wrapped. A transaction inside a batch could carry an incorrectly structured field and still be processed, raising the risk that different software versions would disagree on validity. The fixBatchV1_2 amendment requires the correct structure and activated on Mainnet on October 9, 2026. The Batch feature had not been activated on the mainnet when the vulnerability was identified, and the report did not identify mainnet accounts or funds affected by that bug.

Why it matters

RippleX called the payment engine bug critical because spendable XRP could have been created beyond the total supply in a single validated transaction. XRP's design rests on a hard cap of 100 billion tokens, and all 100 billion XRP were created when the ledger launched in 2012. A silent mint would have undercut that promise. The disclosure also landed in a rough week for crypto security, as Ledger device losses reached an estimated $93.4M. Evernorth, a Ripple-backed company, is preparing to trade on Nasdaq and expects to hold about 473 million XRP once its listing completes.

What the data shows

The numbers around the disclosure line up with the ledger's fixed design. The supply cap is 100 billion tokens, with all 100 billion XRP created at the 2012 launch. Evernorth expects to hold about 473 million XRP once its listing completes, and that listing date moved from Oct. 8 to Oct. 12. Ledger device losses in the same week reached an estimated $93.4M.

Background

The payment engine flaw sits in code written in 2015, long before the current disclosure. The issue is one of several older crypto bugs uncovered this year with help from AI tools, following similar discoveries in the Coldcard wallet and Core Lightning software. XRPL also outlined a change to its security testing process: it plans to retest reported vulnerabilities against release candidates to confirm that fixes work before software releases.

What is still unclear

  • No mainnet accounts or funds were identified as affected by the Batch bug, according to the report.
  • XRPL said it found no evidence the vulnerability had been exploited on any public network, so the practical risk rests on the design flaw rather than an observed loss.

Questions readers ask

Was the XRP Ledger bug exploited?

XRPL reported no evidence that the vulnerability had been exploited on any public network. The report also did not identify any mainnet accounts or funds affected by the Batch bug.

When was the XRP Ledger bug fixed?

The payment engine bug was fixed in xrpld version 3.4.1, released on September 25. The corrected Batch amendment activated on the mainnet on October 9, 2026, the same day the vulnerability report was published.

How much would the exploit have cost?

The report says the cost was a few hundred XRP locked up as reserves, which are returned once the objects are removed, plus ordinary transaction fees. An attacker would also have needed hundreds of mispriced offers.

What is the Batch feature on the XRP Ledger?

Batch lets users combine between two and eight transactions into a single action. Thirty of 35 network validators approved the change, meeting the required two-week supermajority.

Sources · 3 publishers

  1. Coinpedia TIER 3 FIRST REPORT
    XRP News: XRPL Reveals Critical Bug That Could Have Created New XRP
  2. CoinCentral TIER 3
    XRP Ledger Fixes Old Bug That Could Have Created Billions In Fake Tokens
  3. Bitcoin.com News TIER 2
    A Decade-Old XRP Ledger Bug Could Have Minted XRP Out of Thin Air