The XRP Ledger disclosed a critical overflow bug in xrpld versions 3.4.0 and earlier that could have allowed minting XRP beyond the hard cap of 100 billion tokens. The flaw, present since approximately 2015, involved a 64-bit integer overflow when processing payments across multiple order book offers. The cost to exploit was estimated at only a few hundred XRP. Researcher Cayden Liao reported the vulnerability on September 22, 2026, through the XRPL Bug Bounty program, leading to an emergency patch deployed on September 25. No loss of funds was reported and no evidence of exploitation was found.
Source: Read the original article

