Skip to content
XRP Ledger Patches Critical Vulnerability Allowing Creation of New XRP

XRP Ledger Patches Critical Vulnerability Allowing Creation of New XRP

First seen 10 Oct 2026, 18:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 03:36 UTC
  • •A critical vulnerability in the XRP Ledger could have allowed the creation of new XRP.
  • •No evidence of exploitation has been found on public networks according to RippleX.
  • •The vulnerabilities were patched in version 3.4.1 released on September 25, 2026.

The XRP Ledger (XRPL) patched a critical vulnerability that could have allowed attackers to create new, spendable XRP without funding. This flaw, dating back to 2015, was discovered by researcher Cayden Liao and Veria AI and reported on September 22, 2026. The vulnerability exploited a counting error in the payment engine, potentially enabling attackers to generate billions of XRP by manipulating order books. RippleX confirmed no evidence of exploitation on public networks and released the patch in version 3.4.1 on September 25. Additionally, a second vulnerability affecting the Batch transaction feature was also addressed, which could have disrupted transaction validation but did not affect user balances. Both vulnerabilities were disclosed in a report on October 9, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-22
Vulnerability reported
A security vulnerability in the XRP Ledger was reported through the bug bounty program.
Tradingview
2026-09-25
Patch released
RippleX released version 3.4.1 of the XRP Ledger software to fix the vulnerabilities.
Coindesk
2026-10-09
Vulnerability report published
XRPL disclosed the vulnerabilities, detailing their potential impact and the fixes implemented.
Tradingview

More articles in this cluster (14)

Following this threat?

Track RippleX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What was the nature of the vulnerability?
The vulnerability allowed the creation of new XRP through a counting error in the payment engine.
Have there been any reports of exploitation?
No evidence of exploitation has been found on public networks according to RippleX.
What should users do now?
Users should ensure they are running the latest version of the XRP Ledger software to mitigate any risks.