In the cryptocurrency world, a fixed supply is often seen as a sacred guarantee, like the digital equivalent of gold in a vault. However, a vulnerability in the XRP Ledger that had been hiding since 2015 showed just how fragile that confidence can be: a bug in the payment engine allowed the creation of spendable XRP beyond the limit of 100 billion coins.
Researchers Cayden Liao and Veria AI discovered the problem through the bug bounty program on 22 September 2026. RippleX reproduced the attack on a test server and confirmed that an attacker could generate new tokens by exploiting an overflow of a 64-bit integer when summing numerous offers on the built-in exchange. The buyer would pay a tiny amount, while sellers received the full amount — the difference turned into "new" XRP that could then be spent.
All 100 billion XRP were created at the network's launch in 2012, and the protocol initially did not provide for any additional issuance. The bug went unnoticed for a decade because ordinary transactions never came close to the overflow boundary. The "no XRP creation" check relied on the same arithmetic and also missed the anomaly, while the limit on a single account's balance was circumvented by distributing across hundreds of addresses.
The fix was released in xrpld 3.4.1 as early as 25 September — on an emergency basis, without the usual validator vote. More than 80 % of nodes updated the same day. The developers found no traces of exploitation on public networks, but the very fact that the vulnerability existed for so long makes one wonder: who really controls the rules by which our digital money "works"?
For holders of XRP and other crypto assets, the story is a reminder of a simple truth: trust in code is not an abstraction but a daily calculation of risks. Bug bounties and rapid patches work, but they do not eliminate the need for diversification and the understanding that even "immutable" rules sometimes require human intervention.
In the end, the update strengthened protection by adding an overflow check and expanding the invariant counter. The main lesson for anyone holding assets on a blockchain: a system's reliability is measured not only by its past successes but also by its readiness to quickly fix hidden cracks.

