Tradingview XRP Ledger Patches Critical Vulnerability Allowing Creation of New XRP
Article Content
- •A critical vulnerability in the XRP Ledger could have allowed the creation of new XRP.
- •No evidence of exploitation has been found on public networks according to RippleX.
- •The vulnerabilities were patched in version 3.4.1 released on September 25, 2026.
The XRP Ledger (XRPL) patched a critical vulnerability that could have allowed attackers to create new, spendable XRP without funding. This flaw, dating back to 2015, was discovered by researcher Cayden Liao and Veria AI and reported on September 22, 2026. The vulnerability exploited a counting error in the payment engine, potentially enabling attackers to generate billions of XRP by manipulating order books. RippleX confirmed no evidence of exploitation on public networks and released the patch in version 3.4.1 on September 25. Additionally, a second vulnerability affecting the Batch transaction feature was also addressed, which could have disrupted transaction validation but did not affect user balances. Both vulnerabilities were disclosed in a report on October 9, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track RippleX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What was the nature of the vulnerability?
Have there been any reports of exploitation?
What should users do now?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…