XRP Ledger patches flaw that threatened its 100B supply cap

The XRP Ledger has patched a vulnerability that may have existed since 2015 and could have let attackers create and spend XRP without paying the corresponding amount, potentially threatening the token’s 100 billion supply cap. Researchers Cayden Liao and Veria AI reported the flaw to RippleX on Sept. 22. The exploit used a counting error in the ledger’s built-in exchange, allowing accounts to receive large amounts of XRP while paying almost nothing. RippleX reproduced the issue on a standalone server but reported no evidence of exploitation on public networks. The fix was released in xrpld version 3.4.1 on Sept. 25. For XRP traders, the incident underscores protocol security risks, while the patch and lack of known exploitation limit the immediate market impact.
Neutral
The vulnerability posed a serious potential risk to XRP’s supply integrity, so news of it could prompt short-term caution, volatility, or closer scrutiny from traders. However, RippleX reported no evidence that the flaw was exploited on public networks, and the fix was released in xrpld 3.4.1. Those factors reduce the likelihood of an immediate supply shock or lasting confidence damage, supporting a neutral price-impact assessment. Over the longer term, the incident may keep attention on XRPL security and the quality of its upgrade process; continued confidence will depend on effective patch adoption and the absence of evidence of past exploitation.