Overview
- Researchers reported the flaw on Sept. 22 and RippleX shipped a quiet emergency patch on Sept. 25 that added overflow checks to xrpld 3.4.1.
- The bug was a 64-bit integer overflow in the ledger’s payment engine that could wrap totals when one payment consumed many order-book offers and thereby credit XRP that was never paid.
- RippleX reproduced the exploit on a standalone server and confirmed the newly created XRP could be spent in follow-up transactions.
- The project said it found no evidence the flaw was used on public networks and reported no lost funds or compromised keys.
- Developers bypassed the normal amendment timetable so the fix took effect when individual servers upgraded, and operators still running older xrpld versions were urged to update to avoid being amendment-blocked or falling out of sync.