Independent DeFi security desk · Status: operationalMethodology & corrections · Submit an incident
DeFi Safety · Fact checked

XRP Ledger patches decade-old bug that could have minted trillions of XRP

An overflow bug in the XRP Ledger's payment engine could have let an attacker mint about 18 trillion spendable XRP in one transaction.

This article may contain affiliate links. Commercial relationships are disclosed in the affiliate policy.

DeFi Safety — illustration keyed to this article's identifier. Source documents are listed under Sources and are not reproduced here.

What happened

An overflow bug in the XRP Ledger’s payment engine could have let an attacker mint about 18 trillion spendable XRP in one transaction.

Reported details

  • Testing produced spendable XRP, but the disclosure reports no evidence of public-network exploitation and explains why the fix took effect immediately.
  • The flaw was fixed in xrpld 3.4.1 on Sept. 25. Developers found no evidence it was exploited on a public network.

Why this matters

This reads as a change in infrastructure rather than a move in price, and that distinction decides what is worth verifying: whether the underlying record moved, or only the interface around it. If a ledger, custodian or settlement term is unchanged, then anything built on top of it behaves the same too, however the announcement is framed. Subject of the report: XRP Ledger patches decade-old.

Evidence boundary

The scope is limited to what the linked reports state, and where two of them diverge both positions are recorded without either being picked in advance.

What to verify

If XRP Ledger patches decade-old points at a contract or a chain, verify the deployed address and version there. If it describes an internal or corporate change with no on-chain component, the chain is the wrong place to look.

Sources and editorial check time

This information is educational and is not financial, legal, or tax advice.

Sources