Foresight News|Oct 10, 2026 04:56
[Ripple Discloses Two Vulnerability Fixes: Payment Engine Integer Overflow Could Mint XRP Out of Thin Air, Batch Transaction Encapsulation Validation Poses Consensus Risks]
Foresight News reports that Ripple has released a vulnerability disclosure report for xrpld 3.4.1, covering two issues. The XRP overflow in the payment engine has been rated as a critical issue, affecting version 3.4.0 and earlier: the payment engine uses a 64-bit integer to aggregate amounts across multiple orders without overflow checks. When the sum exceeds the upper limit, it wraps around, crediting the full amount to the order side while only charging the wrapped amount to the buyer, effectively minting spendable XRP out of thin air. Exploiting this requires constructing hundreds of malicious orders, costing a few hundred XRP in reserves and fees, and cannot be triggered through normal payments. The report states there is no evidence of this issue being exploited on any public network.
The batch transaction internal encapsulation validation (fixBatchV1_2) was listed as a blocker for activation, affecting versions 3.3.0 and 3.4.0: the XLS-56 batch functionality requires internal transactions to be encapsulated in the RawTransaction field, but the server did not enforce this. Object type fields without templates could be used for encapsulation, while fields with templates would be rejected, potentially causing consensus discrepancies between nodes running different versions. If BatchV1_1 were activated without fixing this issue, there would be risks of network activity disruption or malformed records being left in the ledger. This issue was resolved through the fixBatchV1_2 amendment in version 3.4.1, which was activated on the mainnet on October 9. The report states that this issue did not result in any financial loss or private key leaks. The payment engine overflow fix took effect with the release of version 3.4.1 on September 25, without requiring an amendment process. The payment engine issue was submitted with a proof of concept by Cayden Liao and Veria AI through the bug bounty program.
Share To
HotFlash
APP
X
Telegram
CopyLink