XRP Ledger patches flaw that could create spendable XRP
The XRP Ledger patched a long-standing software flaw that could have allowed attackers to create and spend XRP beyond the network’s 100 billion-token supply cap. RippleX said investigators found no evidence the vulnerability had been exploited on a public network, though the supplied reporting does not independently establish whether it was ever used. Researcher Cayden Liao and Veria AI reported the flaw through the XRPL bug-bounty program on September 22, 2026. RippleX engineers reproduced the attack on a standalone server and confirmed that excess XRP could be spent in later transactions, according to the vulnerability disclosure. The flaw involved the ledger’s built-in exchange, where users post offers to trade one asset for another. A carefully constructed payment could consume offers from hundreds of accounts at once. When the software added up the XRP involved, its integer counter could overflow and wrap to a much smaller number. Sellers could then receive the full amounts listed in their offers while the buyer was charged far less, potentially creating spendable XRP without equivalent payment.