How Critical XRP Ledger Bug Nearly Unleashed Unlimited XRP Mint
developers recently released a vulnerability disclosure report for the latest reference server implementation of the XRP Ledger protocol, xrpld 3.4.1.xrpld 3.4.1 launched on September 25, 2026, as an emergency release to fix critical security vulnerabilities in the XRPL protocol.Along these lines, an official report released on October 9, 2026, provides vulnerability disclosure information for the two bugs fixed in the xrpld 3.4.1 release: a Batch inner transaction wrapper validation error and a payment engine XRP overflow error affecting XRPL v3.4.0 releases and earlier.Of particular concern is the payment engine overflow error, which would have been critical if exploited, as an attacker could have created spendable XRP far beyond the total supply in a single validated transaction. The minted XRP would then sit in ordinary accounts and could be moved, traded, or sent to exchanges.About payment engine XRP overflow errorOn September 22, 2026, a researcher reported through the XRPL Bug Bounty program that an integer overflow in the payment engine could be exploited to create XRP from nothing.Using a set of specially crafted offers and a single payment, an attacker could mint new XRP in violation of the XRP Ledger's intended rules and spend it like any other XRP.The overflow could occur where the payment engine adds amounts from a single payment that consumes many offers from the order book. XRP balances are represented as integers with a fixed maximum. When a sum surpasses that maximum, it does not fail with an error but rather wraps around to a small number. The engine paid each offer owner their full amount individually but charged the buyer only the wrapped-around total. The difference was new XRP that should never have existed.The XRP Ledger has a built-in invariant (safety check) that ensures no transaction creates new XRP. However, this summed balance changes the same way, so it wrapped around identically and detected nothing.Although investigation revealed that the bug had been present since the current payment engine was written in 2015, it was only identified and reported last month.Fix released in xrpld 3.4.1The fix for the payment engine XRP overflow error shipped in xrpld 3.4.1, while no evidence was found that this issue was exploited on any public network.Given the severity of the issue, the fix did not go through the amendment process, marking the first time a change to transaction processing was deliberately shipped this way since the amendment system was introduced more than ten years ago.The XRP overflow fix applies immediately upon upgrade to v3.4.1, with XRPL server operators urged to upgrade to the latest version to maintain sync with the network.