01
RippleX disclosed a critical bug in the XRP Ledger's core payment engine on October 9, 2026.
02
The flaw was a 64-bit integer overflow that dates back to when the payment engine was written in 2015.
03
It could have let someone mint spendable XRP beyond the fixed 100 billion supply cap.
04
Researcher Cayden Liao and Veria AI reported it through the XRPL bug bounty program on September 22.
05
RippleX reproduced the exploit, confirmed the new XRP was spendable, and raised its severity to critical.
06
A fix shipped in xrpld 3.4.1 on September 25, three days after the report.
07
The patch skipped the XRP Ledger's normal public validator vote, which developers said would have exposed the bug while it was still live.
08
RippleX says it found no evidence the bug was ever exploited on the public network.