XRP Ledger fixed a decade-old security bug that could have created 18 trillion XRP. The researcher received a $250,000 bounty.
The XRP Ledger has fixed a critical security flaw that could have allowed attackers to create 18 trillion XRP. Developers disclosed the vulnerability after securing the RippleX network and XRP Ledger Foundation. In the meantime, security researcher Cayden Liao has been rewarded with $250,000 for his discovery of the problem.
XRP Ledger Fixes Critical Supply Vulnerability
The vulnerability was in the network’s payment engine and was an overflow bug. If a special transaction had been designed, the researcher said, it could have produced spendable XRP that went beyond the fixed supply. As a result, attackers could have threatened the network’s financial integrity.
The XRP Ledger was introduced in 2012 with a cap of 100 billion XRP. Unlike other cryptocurrencies, XRP can’t be mined or staked on the XRP network. Furthermore, small amounts of XRP are permanently lost in transactions due to fees, which are slowly decreasing the number of XRP in circulation.
But the recently revealed flaw could have compromised this supply restriction. Liao said his team developed a proof of concept that could generate approximately 18 trillion XRP through one transaction. This is about 184 times the initial supply in the network.
XRP is also a significant cryptocurrency, having a market cap of around $94 billion. So, if the asset was compromised, it could have affected the trust in the asset and the market. However, attackers have not been found to exploit the flaw on public networks, developers said.
Emergency Patch Secured the XRP Ledger Network
The vulnerability was disclosed on XRPL bug bounty on September 22, 2026. Later, a patch was released by the developers on September 25, with the new version of xrpld being 3.4.1. The disclosure says that over 80% of default validators upgraded their software on that day.
Importantly, developers did not go through the normal two-week amendment vote on the validators, but rather went through an emergency process. This strategy enabled them to deal with the threat without revealing technical details to the public. The coordinated disclosure came on October 9, following developers’ securing of the network.
Moreover, the discovery revealed that even after the software had been extensively reviewed, it could still be vulnerable to serious security issues. The bugged code was from 2015 and the exploit was said to be a combination of 2 bugs. These weaknesses individually may have seemed less threatening in previous reviews.
Liao’s team won the maximum $250,000 prize for discovering the flaw in the program. The discovery was an “unusually significant security finding,” the researcher said. The claimed proof-of-concept, however, was an attack on public users, not actual damage.
XRP Ledger Confirms No Exploitation After Emergency Patch
In the past few years, the XRP Ledger has been the subject of many audits and security challenges. The disclosure says the network has awarded over $1 million in bug bounties. Such programs urge researchers to responsibly report vulnerabilities rather than leaving them open for exploitation by attackers.
The incident serves as a reminder of the need for timely software updates on blockchain networks. The validators are crucial as their software ensures the proper functioning and security of the ledger. So, if the developers find out that there are critical vulnerabilities, then timely upgrades can help to minimize exposure.
Despite the critical nature of the potential exploit, there were no reports of any unauthorized creation of XRP. Developers also did not see any evidence that any public network users lost money due to this flaw. As a result, a large theoretical threat was resolved without a public network incident.





Be the first to comment