A critical XRP Ledger flaw could have allowed an attacker to create XRP beyond the network's 100 billion-token cap by exploiting an integer overflow during payments that consumed multiple order-book offers. The vulnerability affected xrpld 3.4.0 and earlier and was reported through the XRPL Bug Bounty program by researcher Cayden Liao on September 22, 2026. RippleX reproduced the exploit on a standalone server and confirmed that excess XRP could be spent in later transactions, but found no evidence that it was used on a public network. An emergency xrpld 3.4.1 release on September 25 patched the issue outside the ledger's usual validator amendment process; the vulnerability was publicly disclosed on October 9. RippleX reported no fund losses, compromised keys or consensus failures linked to the flaw.