Hacks & Exploits
Ripple Addresses Critical Bug Preventing Unauthorized XRP Minting
Ripple has announced the resolution of a critical software bug that existed since 2015, which had the potential to enable unauthorized minting of XRP. This vulnerability, if exploited, could have led to the creation of billions of XRP beyond the established cap of 100 billion tokens.
The bug was linked to the XRP Ledger's code, specifically in versions 3.4.0 and earlier, and was quietly patched in September 2026. The public disclosure of the issue occurred on October 9, 2026. Investigators confirmed that the bug had never been exploited on the public network, maintaining the integrity of the XRP supply.
The flaw allowed an attacker to exploit a 64-bit integer used for calculating XRP amounts during transactions, potentially allowing them to create XRP that did not exist. Fortunately, existing safety checks failed to catch this issue, but the Ripple team acted quickly to implement an emergency fix.
This development is expected to bolster confidence among XRP investors, particularly as the market navigates regulatory challenges and competition. Observers are advised to monitor further communications from Ripple’s leadership and any significant announcements regarding XRP’s adoption and technological advancements.
New Facts on Ripple's XRP Bug
- A critical bug in the XRP Ledger's payment software could have allowed unauthorized minting of XRP, potentially unnoticed since 2015.
- The flaw was reported by researcher Cayden Liao and Veria AI through the XRPL bug bounty program on September 22, 2026.
- The bug affected versions of the software up to xrpld 3.4.0.
- RippleX released a fix in server software version 3.4.1 on September 25, 2026, which took effect immediately upon operator upgrades.
- This fix was implemented without the usual 80% validator backing to avoid exposing the bug in open code.
- More than 80% of default validators upgraded on the release day, before the fix's code was publicly disclosed.
FAQ
What was the critical bug discovered in Ripple's software?
The critical bug allowed for the potential unauthorized minting of XRP, which could have led to the creation of billions of XRP beyond the established cap of 100 billion tokens.
When was the bug in Ripple's software patched?
The bug was quietly patched in September 2026.
Has the bug ever been exploited on the public network?
Investigators confirmed that the bug had never been exploited on the public network, maintaining the integrity of the XRP supply.
What specific versions of the XRP Ledger were affected by the bug?
The bug was linked to the XRP Ledger's code in versions 3.4.0 and earlier.
How might this bug resolution impact XRP investors?
The resolution of the bug is expected to bolster confidence among XRP investors, especially as the market faces regulatory challenges and competition.