XRP Ledger Emergency Patch Bypasses Standard Validator Voting Process
A decade-old vulnerability in the XRP Ledger could have allowed attackers to create spendable XRP without paying for it, threatening the cryptocurrency’s fixed supply of 100 billion tokens. Ripple’s development team released an emergency software update to eliminate the flaw before researchers found evidence of any exploitation on public networks.
The vulnerability, disclosed on October 9, 2026, reportedly dates back to 2015. Researchers Cayden Liao and Veria AI discovered the issue through the XRP Ledger’s bug bounty program and reported it on September 22. RippleX, Ripple’s developer division, reproduced the attack and confirmed that the newly created XRP could be spent in subsequent transactions.
How the XRP Supply Bug Worked
The vulnerability involved an integer overflow in the XRP Ledger’s payment engine. The system processes transactions through its built-in exchange, where users place offers to trade one asset for another.
An attacker could have exploited this mechanism by creating hundreds of accounts and placing offers involving unusually large amounts of XRP. A single carefully constructed payment could then consume all those offers.
The payment engine would calculate the total XRP owed across the offers. However, the combined amount could exceed the maximum value its numerical counter could represent, causing the total to wrap around to a much smaller number.
Consequently, the selling accounts would receive their full payments while the buyer would pay only the incorrectly calculated amount. This discrepancy could effectively create new XRP.
The ledger’s existing safeguard, designed to detect unauthorized XRP creation, also relied on calculations vulnerable to the same overflow. As a result, it could fail to detect the newly created tokens.
RippleX confirmed that the attack required only a few hundred XRP to establish the necessary accounts, along with transaction fees.
Emergency Fix Bypassed the Usual Voting Process
Ripple released XRP Ledger server software version 3.4.1 on September 25 to address the vulnerability. Unlike conventional protocol changes, the payment-engine fix took effect as individual operators upgraded their servers.
The decision marked an exceptional departure from the ledger’s usual amendment process, which generally requires more than 80% support from trusted validators sustained over two weeks.
RippleX explained that following the normal process could have exposed the vulnerability publicly while the network remained vulnerable during the voting and activation period.
More than 80% of default trusted validators had upgraded on the release day, according to the official disclosure.
The vulnerability report, published October 9, confirmed that investigators found no evidence of exploitation on public networks. The incident highlights the importance of independent security research and rapid coordination across cryptocurrency infrastructure.
Although Ripple addressed the immediate threat, the episode raises important questions about how decentralized networks should balance emergency security measures with transparent governance. RippleX emphasized that the exceptional response does not change the ledger’s established approach to future protocol amendments.