XRPL patched two vulnerabilities enabling possible XRP creation
XRPL patched two vulnerabilities enabling possible XRP creation
Developers of the XRP Ledger released fixes addressing two vulnerabilities that could have allowed new XRP issuance and halted consensus.
First vulnerability: incorrect debit handling
The first bug could let a payment recipient receive more XRP than were debited from the sender, potentially minting tokens unintentionally.
According to the development team, this flaw may have existed since 2015, though they report no evidence of real-world exploitation to date.
Second vulnerability: ledger divergence risk
The second issue could cause disagreement between servers and disrupt ledger validation, with a risk of halting transaction confirmations across the network.
Developers noted that the mainnet was not harmed because the problematic protocol feature had not been activated before the patch was prepared.
Deployment and activation timeline
Both fixes were included in the xrpld build 3.4.1 released on 25.09, and the protocol update for the second issue was activated on 09.10.
Network operators were advised to upgrade to the patched xrpld version promptly to ensure consistent consensus and avoid potential replay or divergence scenarios.
Current status and recommendations
The project team confirmed no detected exploitation and emphasized that upgrades were necessary to eliminate any remaining risk and to protect transaction integrity.
- xrpld 3.4.1 contains both code fixes delivering corrective behavior for affected transaction paths.
- The protocol activation on 09.10 addresses the consensus divergence vector by changing validation conditions.
- Operators are recommended to run the patched build and verify peer compatibility to maintain a healthy network state.
In summary, the XRPL team closed two serious issues that could have resulted in unintended token creation or halted confirmations, and they rolled out fixes through the xrpld release and subsequent protocol activation.
Related posts

