XRP Ledger Overflow Bug Could Have Minted XRP From Nothing
A disclosure published October 9 shows an integer overflow in the XRP Ledger payment engine could have created spendable XRP from nothing; the fix shipped in xrpld 3.4.1 and no exploitation was found.

The XRP Ledger overflow bug disclosed on Friday, October 9, 2026, could have let an attacker create spendable XRP from nothing, breaking the network's fixed supply, according to a vulnerability disclosure report published on the XRP Ledger developer site. The fix shipped in the xrpld 3.4.1 server release on September 25, and the report said there was no evidence the flaw had been exploited on any public network.
What happened
The disclosure describes an integer overflow in the ledger's payment engine. A single payment that consumed many offers on the ledger's built-in exchange summed the amounts owed using integers with a fixed maximum. When that sum exceeded the maximum, it did not fail with an error but wrapped around to a small number. The engine paid each offer owner in full, while charging the buyer only the wrapped-around total. The difference was newly minted XRP that could be spent like any other.
The ledger runs an invariant check after transactions to confirm that no XRP has been created, but that check summed balance changes the same way and wrapped identically, so it missed the problem. CoinDesk reported that a separate limit on how much XRP a single account can receive would not have triggered either, because an attack could spread the proceeds across hundreds of accounts. The researchers' method needed only a few hundred XRP to open those accounts, most of which could be recovered, plus fees.
The flaw, believed to date to 2015, was found by researcher Cayden Liao and Veria AI and reported internally on September 22, CoinDesk said. Engineers at RippleX, Ripple's developer arm, reproduced the attack on a standalone server and confirmed the minted XRP could be spent in a later transaction. Developers shipped the fix in xrpld 3.4.1 without initially disclosing what it repaired. Starting with that release, the payment engine checks for overflow when summing amounts across offers, and a transaction that would overflow now fails cleanly.
The same release fixed a second, unrelated issue in the Batch feature, which lets one account submit up to eight transactions as a unit. A validation gap meant inner transactions could be wrapped in the wrong field, which could have caused a consensus disagreement between server versions. That amendment had not been activated on Mainnet, so no funds were affected. Its fix, the fixBatchV1_2 amendment, became enabled on Mainnet on October 9, and servers that have not upgraded to 3.4.1 or newer are now amendment blocked.
Why it matters
The XRP Ledger overflow bug goes to the core of the asset's design. All 100 billion XRP were created when the ledger launched in 2012, and the software is meant to make further issuance impossible. An attacker able to mint XRP and sell it on exchanges would have undercut a supply cap that institutions using the network rely on, CoinDesk noted.
It is also part of a broader pattern. CoinDesk placed the disclosure within a run of long-hidden crypto flaws surfaced with AI help since July, including the Coldcard wallet bug behind the theft of at least 1,367 BTC and vulnerabilities that forced Core Lightning to warn bitcoin node operators. AI-assisted code review cuts both ways, as we noted when covering the Anthropic OSS Scanner: the same tools that help defenders find bugs can help attackers. For XRP's market structure, our earlier report on XRP ETF inflows shows how much institutional money now depends on the integrity of the ledger.
What's next
Node operators must run xrpld 3.4.1 or newer to stay in sync now that fixBatchV1_2 is live, the disclosure said. The report credited Cayden Liao and Veria AI for the original overflow report and proof of concept, alongside the XRPL Foundation, RippleX engineers and participants in the Sherlock Attackathon, the security contest whose findings led to the Batch fix. Market attention will turn to whether the disclosure affects sentiment toward XRP, and to whether further AI-assisted reviews surface other long-dormant issues in the ledger's code.
The call
Polymarket asks whether XRP will dip to $1.20 at any point in October. The market resolves Yes if any Binance XRP/USDT one-minute candle during the month has a low at or below $1.20; otherwise No. When Called It checked it at 05:30 UTC on 2026-10-10, "No" traded at 77%.
Our call: No. The XRP Ledger overflow bug was patched before disclosure, the report found no exploitation, and the related Batch fix is now active on Mainnet, so the disclosure itself removes rather than adds a tail risk. A broader crypto selloff could still push XRP lower, but the market currently favors the floor holding. We will check the result on November 1, 2026. This is a dated market call for the Called It record, not investment advice.
This article is for information only and is not investment advice. Calls are editorial forecasts, logged with market odds at the time of publication and kept on the record.