BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

XRPL patched critical integer overflow, risked unauthorized XRP creation

A critical software vulnerability in the XRP Ledger (XRPL) protocol has been patched following the discovery of a flaw that could have allowed malicious actors to generate XRP tokens beyond t

AnonymousCryptoCompass newsroom
October 11, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

A critical software vulnerability in the XRP Ledger (XRPL) protocol has been patched following the discovery of a flaw that could have allowed malicious actors to generate XRP tokens beyond the limits set by the network’s rules.

Integer overflow exposed supply risk

The issue emerged from an integer overflow in XRPL’s payment engine, a core component responsible for processing payments involving multiple assets on the ledger. Under certain conditions, transactions that consumed a large number of specially crafted offers could cause the system to miscalculate the amount of XRP owed by the sender.

Instead of failing transactions that surpassed the representable numerical range, the ledger would incorrectly “wrap around” the excess, reducing the calculated total to a much smaller figure. Recipients would receive full payment, but the sender would only lose the incorrect, reduced total of XRP, rather than the true sum.

This discrepancy meant that attackers could artificially inflate the supply of XRP, effectively bypassing the cryptocurrency’s supply limitations. The vulnerability also undermined the network’s detection safeguards, as its anti-creation mechanisms depended on the same arithmetic, allowing unauthorized XRP generation to go undetected.

During controlled testing, researchers confirmed the flaw enabled the unauthorized creation and subsequent transfer of XRP that did not exist prior to the exploit.

Mini dictionary: Integer overflow, a programming error where a calculation exceeds the computer’s storage capacity, can cause extremely large numbers to “wrap around” to a much smaller value, leading to serious security risks in financial and cryptographic systems.

Disclosure and emergency patch

Security researchers Cayden Liao and Veria AI reported the vulnerability to XRPL’s bug bounty program on September 22. After reviewing the discovery, developers upgraded its classification from major to critical due to the risk of systemic compromise to the network.

Developers concluded that if the usual protocol amendment process was followed, the vulnerability could become public before a sufficient number of validators had protected the network, increasing the likelihood of exploitation.

On September 25, version 3.4.1 of the core implementation, xrpld, was released, adding additional overflow checks and reinforcing supply-protection mechanisms. Unlike standard protocol changes, which require over 80% of validators to approve an amendment for two consecutive weeks, this emergency update took effect as validators upgraded their software immediately.

By September 25, more than 80% of trusted validators had deployed the patched version, closing the vulnerability before it could be broadly exploited. Coinpaper previously covered the XRPL emergency release, though the full technical context became public only in October.

Additional vulnerabilities and governance debate

In an October 9 report, researchers also identified a separate problem involving Batch transactions that threatened to disrupt consensus across the XRPL network. Developers mitigated this risk through an additional amendment, fixBatchV1_2, which went live alongside BatchV1_1 on October 9.

These incidents follow a series of upgrade delays on XRPL, sparking ongoing discussion about network governance and the need for rapid, coordinated responses to critical security issues. The events have once again highlighted questions surrounding decision-making and transparency within the XRP Ledger community.

The post XRPL patched critical integer overflow, risked unauthorized XRP creation appeared first on COINTURK NEWS.