XRP News: XRPL Serious vulnerability discovered, which could have potentially led to the creation of new XRP.
XRP Ledger ( XRPL ) disclosed two software vulnerabilities on October 9, 2026, including a severe vulnerability that could have allowed attackers to create new, spendable XRP. The second vulnerability affected the Batch transaction function of the network, potentially disrupting transaction verification.
According to official reports, a vulnerability in the payment engine was fixed in version xrpld 3.4.1, which was released on September 25th. XRPL indicates that there is no evidence that this vulnerability has been exploited on any public networks.
XRPL The vulnerability could potentially create new XRP.
This serious vulnerability affects the way the payment engine calculates the required quantity of XRP when completing transactions across multiple quotes in the order book. When the combined amount exceeds the maximum value supported by the system, an overflow may occur during the calculation. This could result in the payment engine charging the buyer a amount of XRP that is less than the amount credited to the quote owner's account, effectively creating a new XRP.
To exploit this vulnerability, it is necessary to carefully prepare an order book containing hundreds of quotes with abnormally high prices, and then initiate a specific payment transaction. This vulnerability cannot be triggered through ordinary payments or transactions.
A researcher reported this issue on September 22, 2026, through the XRPL vulnerability bounty program. The RippleX engineering team reproduced the vulnerability and confirmed that any XRP created through this vulnerability could be spent.
This issue has been fixed in version 3.4.1. Developers have added a check mechanism to prevent calculation overflow and enhanced the system's protection against unauthorized creation of XRP.
The second vulnerability affects batch transactions of XRPL.
The second vulnerability relates to the Batch transaction function of XRP Ledger. This function allows users to submit multiple transactions together. This flaw enables a transaction within a batch to use fields with incorrect structures, yet the server may still accept and process that transaction.
This poses a risk: different versions of the XRPL software may reach different conclusions regarding the validity of a particular transaction. Such disagreements could prevent verifiers from reaching a consensus and disrupt ledger verification.
According to the report, this issue does not allow attackers to bypass transaction signatures, nor does it directly steal funds.
XRPL addressed this vulnerability through the fixBatchV1_2 proposal, which requires transactions to use the correct structure. At the time the vulnerability was discovered, the Batch feature had not yet been activated on the mainnet; therefore, the report did not indicate that any mainnet accounts or funds were affected.
XRPL Enable Batch Security Fix
XRPL Developers and validators have withdrawn their support for the original Batch proposal in order to reset its activation timeline, while the team is preparing a fix plan.
The revised proposal was supported and activated on the mainnet on October 9, 2026, which is the same day as the vulnerability report was released.
The report also mentions that adjustments will be made to the security testing process. XRPL plans to retest the reported vulnerabilities on the candidate versions to confirm that the fixes are effective before the software is released.
What Owners of XRP Need to Know
Both of these vulnerabilities have been addressed, and XRPL also indicates that there is no evidence of serious payment engine vulnerabilities being exploited on public networks. The report does not prove that these two vulnerabilities caused any actual financial losses or an increase in XRP. The fixes for the payment engine issues are included in the xrpld version 3.4.1, while the Batch issue was resolved through the fixBatchV1_2 proposal.
The report does not require XRP holders to transfer funds or change their private keys. This software upgrade is mainly related to the operators of the XRPL servers, who need to use a compatible version to maintain synchronization with the network.
CoinPedia Disclaimer
CoinPedia has been providing accurate and timely updates on cryptocurrencies and blockchain since 2017. All content is created by our team of analysts and journalist experts, and follows strict editorial guidelines based on E-E-A-T (experience, professionalism, authority, credibility). Each article undergoes fact verification against reliable sources to ensure accuracy, transparency, and reliability. Our review policy ensures an objective assessment when recommending exchanges, platforms, or tools. We are committed to keeping readers informed about the latest developments in the cryptocurrency and blockchain fields, covering everything from startups to industry giants.
Investment Disclaimer:All views and opinions shared in this article represent the author's personal views on the current market situation. Please conduct your own research before making investment decisions. Neither the author nor the publisher assumes any responsibility for your financial choices.
Sponsorship and Advertising:Sponsored content and affiliate links may appear on this site. Advertisements will be clearly marked, and the editorial content is always independent of advertising partners.












