XRP Ledger patches payment bug that could have breached 100 billion supply cap
The XRP Ledger disclosed an integer-overflow flaw in its payment engine on October 9, 2026. The bug could have let an attacker create spendable XRP beyond the network's 100 billion token cap.
- An emergency update, server software version 3.4.1, was released on September 25, before the flaw was published.
- XRPL said it found no evidence the vulnerability had been exploited on any public network.
- Triggering it required hundreds of deliberately priced offers followed by a single payment, not one transaction.