Crypto Briefing • October 10th 2026, 6:05 AM
XRP Ledger discloses overflow bug that could have minted XRP beyond its supply cap
Key Summary
The XRP Ledger has identified a critical bug that could have allowed an attacker to create XRP beyond its 100 billion token limit. The bug, which was patched in September, was discovered by researcher Cayden Liao through the XRPL Bug Bounty program. No evidence suggests the bug was exploited on a public network.
Please see our real time news feed on our Home Page
XRP Ledger Discovers Overflow Bug, Potentially Minting XRP Beyond Supply Cap
Bug Discovery and Patching
The XRP Ledger has disclosed a critical bug that could have let an attacker create XRP out of thin air, beyond the network's hard limit of 100 billion tokens. The vulnerability was reported on September 22, 2026, by researcher Cayden Liao through the XRPL Bug Bounty program. RippleX, Ripple's developer arm, confirmed the issue.How the Bug Worked
The software used a 64-bit integer to add up XRP amounts when a single payment pulled from multiple offers on the order book. If that running total grew past the largest number the integer could hold, it wrapped around. The result was a number far smaller than reality. An attacker could exploit that gap to spend XRP that did not exist. The ledger's books would look balanced, while the actual supply quietly ballooned. The existing safety checks did not catch it. When the inflated balances were scattered across many accounts, the system's guardrails failed to flag the discrepancy.Cost and Impact
The cost of pulling this off was strikingly low. According to the disclosure, the exploit required specially crafted offers from hundreds of accounts, costing only a few hundred XRP in reserves and fees. Most of that outlay would have been recoverable.Public Disclosure and Response
A quiet fix, then a public disclosure The vulnerability was reported on September 22, 2026, by researcher Cayden Liao through the XRPL Bug Bounty program. RippleX, Ripple's developer arm, confirmed the issue. Three days after the report, on September 25, 2026, an emergency release went out: xrpld 3.4.1. The fix also skipped the usual amendment process. Normally, changes to the XRP Ledger's rules go through a validator voting procedure before taking effect. This one was deployed immediately instead. The public disclosure came on October 9, roughly two weeks after the patch shipped. The team reported no loss of funds, no compromised keys and no consensus problems tied to the bug.Historical Context
A decade in hiding The flaw is thought to have existed since the payment engine was first built, around 2015. That means the code processed payments for years with a latent overflow sitting inside it.Conclusion
For XRP holders, the immediate takeaway is reassuring. There is no evidence the bug was exploited, and the integrity of the token supply appears intact. The decision to bypass the amendment process deserves attention. A known path to unlimited XRP creation is not something you want waiting on a governance vote. Emergency patches that skip normal procedures put a lot of trust in the core development team, and the network's security depended on validators and node operators upgrading quickly.#XRP#US#Crypto#SEC