FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.8T -0.5%24h Vol $58.6B -23%Fear & Greed 64/100Alts Index 51/100
BTC.D 59.7% +0.4%Stable.D 9.5% +0.1%ETH.D 10.9% +0.1%Others.D 19.9% -0.6%
DRV$0.5069+36.59%•RLC$1.132+31.92%•BP$1.242+26.47%•CAP$0.0921+24.98%•BAT$0.1355+21.8%•Q$0.0277+19.86%•CARDS$0.3039+18.84%•LPT$1.956+12.05%•BTW$1.543+11.67%•WLD$0.5487+11.32%•
SENT$0.0201-10.67%•0G$0.2574-8.17%•USELESS$0.1774-7.59%•PYTH$0.0783-6.99%•ZRO$1.955-6.23%•STONK$0.1475-6.03%•SOON$0.3087-5.89%•JST$0.1371-4.13%•S$0.0429-3.75%•CC$0.1197-3.43%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      XRP Ledger Fixed Two Dangerous Bugs: One Could Disrupted XRP Issuance, and Other Could Brought Network to Halt

      • A vulnerability was found in the XRP Ledger that could allow XRP to be issued without backing.
      • To fix the bug, Ripple Labs released XRPL 3.4.1.
      • The update also made it possible to protect the XRP Ledger from forged batch transactions.

      The XRP Ledger (XRPL) blockchain team published a report on two vulnerabilities in the xrpld software that could have jeopardized network operations and allowed XRP to be created without proper backing. Both issues were fixed in version 3.4.1, released on September 25. 

      According to the team, there is no evidence that the integer overflow vulnerability was exploited on public networks, and the batch transaction issue did not affect the mainnet because the relevant protocol update had not yet been activated.

      One Vulnerability Could Have Allowed XRP to Be Issued Without Backing

      The first issue was discovered on September 22, 2026, through the XRPL bug bounty program. An integer overflow in the payment engine could have allowed an attacker to create XRP out of thin air by using specially crafted offers in the order book and a single payment.

      When processing hundreds of offers, the system could incorrectly sum XRP amounts: instead of throwing an error, an overly large number would wrap into a small one. At the same time, offer owners would receive the full amounts, while the buyer would pay only a much smaller figure. A standard check meant to ensure that a transaction does not create new XRP also failed to detect the issue due to a similar overflow.

      By the team’s estimate, the bug could have existed since 2015 — when the current payment engine was introduced. It was fixed in xrpld 3.4.1: the system now checks for overflow when calculating totals and rejects invalid operations. The team also strengthened balance checks.

      Batch Transaction Bug Threatened Network Consistency

      The second vulnerability was found during a re-review of the Sherlock Attackathon results. On September 18, Denis Angell of the XRPL Foundation confirmed that the previous fix was incomplete. Later, Mayukha Vadari of RippleX determined that the bug could cause discrepancies between versions of the server software.

      The issue involved the Batch mechanism, which allows up to eight transactions to be bundled into a single batch. The server did not verify whether each inner transaction was wrapped in the required RawTransaction field. As a result, different versions of xrpld could interpret the validity of the same operation differently, which under certain conditions threatened to halt the validation of new ledgers.

      The team fixed the bug via the fixBatchV1_2 update, which was activated on mainnet on October 9. Before activation, the issue could not be exploited to impact mainnet because the corresponding BatchV1_1 function remained inactive.

      Both fixes were included in xrpld 3.4.1. The team also plans to re-verify each patched vulnerability on new release candidates before finally closing the relevant reports.

      Earlier in 2026, Ripple Labs also worked on strengthening security and expanding the capabilities of the XRP Ledger. In March, RippleX researchers presented an approach to confidential transfers for multi-purpose tokens designed to protect user data. 

      In April, the company announced a multi-phase plan to prepare XRPL for quantum computing threats, outlining a transition to post-quantum cryptography by 2028. And in October, Brazil’s CSD BR launched the first stage of a partnership with Ripple Labs to tokenize shares of BTG Pactual investment funds on XRPL.

      Сообщение XRP Ledger Fixed Two Dangerous Bugs: One Could Disrupted XRP Issuance, and Other Could Brought Network to Halt появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud