XRPL Reveals Critical Bug That Could Have Created New XRP

Coinmama
Blockonomics


The XRP Ledger (XRPL) disclosed two software vulnerabilities on October 9, 2026, including a critical bug that could have allowed attackers to create new, spendable XRP. The second flaw affected the network’s Batch transaction feature and could have disrupted transaction validation.

According to the official report, the payment engine bug was fixed in xrpld version 3.4.1, released on September 25. XRPL reported no evidence that the vulnerability had been exploited on any public network.

XRPL Bug Could Have Created New XRP

The critical vulnerability affected how the payment engine calculated the XRP required to complete trades across multiple offers in an order book. The calculation could overflow when the combined amount exceeded the maximum value supported by the system. This could cause the payment engine to charge a buyer less XRP than the amount credited to offer owners, effectively creating new XRP.

Exploiting the bug required a carefully prepared order book containing hundreds of offers with unusually high prices, followed by a specific payment transaction. The vulnerability could not be triggered through ordinary payments or trades.

Phemex
Add Coinpedia as a trusted source in Google NewsAdd Coinpedia as a trusted source in Google News

A researcher reported the issue through the XRPL Bug Bounty program on September 22, 2026. The RippleX engineering team reproduced the bug and confirmed that any XRP created through the flaw could be spent.

The issue was fixed in version 3.4.1. Developers added checks to prevent the calculation from overflowing and strengthened the system’s safeguards against unauthorized XRP creation.

Second Bug Affected XRPL Batch Transactions

The second vulnerability involved the XRP Ledger’s Batch transaction feature, which allows users to submit multiple transactions together. The flaw allowed a transaction inside a batch to use an incorrectly structured field. The server could still accept and process the transaction.

This created a risk that different versions of XRPL software could disagree on whether a transaction was valid. Such disagreements could prevent validators from reaching consensus and interrupt ledger validation.

The issue did not allow attackers to bypass transaction signatures or directly steal funds, according to the report.

XRPL addressed the flaw through the fixBatchV1_2 amendment, which requires transactions to use the correct structure. The Batch feature had not been activated on the mainnet when the vulnerability was identified, so the report did not identify any mainnet accounts or funds affected by this bug.

XRPL Activates Batch Security Fix

XRPL developers and validator operators withdrew support for the original Batch amendment to reset its activation timeline while the team prepared the fix.

The corrected amendment gained support and activated on the mainnet on October 9, 2026, the same day the vulnerability report was published.

The report also outlined a change to the security testing process. XRPL plans to retest reported vulnerabilities against release candidates to confirm that fixes work before software releases.

What XRP Holders Need to Know

Both vulnerabilities have been addressed, and XRPL reported no evidence that the critical payment engine bug had been exploited on a public network. The report does not establish that either flaw caused an actual loss of funds or an increase in XRP supply. The payment engine fix is included in xrpld version 3.4.1, while the Batch issue was addressed through the fixBatchV1_2 amendment.

The report does not instruct XRP holders to move their funds or change their private keys. The software upgrade is relevant to XRPL server operators, who need compatible versions to remain synchronized with the network.

Was this writing helpful?

Story Ends Here

Trust with CoinPedia:

CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.

Investment Disclaimer:

All opinions and insights shared represent the author’s own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.

Read the Next News



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*