XRP Ledger Issues Emergency Security Release Ahead of Oct. 9 Upgrade

XRPL has released version 3.4.1 as an emergency security update, adding fixBatchV1_2 ahead of the expected Oct. 9 Batch upgrade.

XRP Ledger Issues Emergency Security Release Ahead of Oct. 9 Upgrade

In the official XRPL 3.4.1 release notes, developers said the update fixes “security-sensitive issues” in the protocol and urged server operators to upgrade as soon as possible. The release introduces a new amendment called fixBatchV1_2, with its default validator vote set to “Yes.”

The timing matters because the BatchV1_1 upgrade was recently pushed back to Oct. 9 after validator support briefly fell below the required threshold and reset its two-week countdown.

Validators Are Being Told to Upgrade Now

XRPL says fixBatchV1_2 has already gained support from a supermajority of validators and is expected to become enabled on Oct. 9 if that support holds.

Servers that fail to update to xrpld 3.4.1 before activation could become amendment blocked, meaning they would no longer be able to stay synchronized with the rest of the network.

The release also includes a fix that rejects Batch inner transactions using the wrong wrapper, plus additional integer-arithmetic hardening in the payment engine and ledger helper code.

XRPL’s Batch rollout now depends on validators adopting the emergency 3.4.1 release.
XRPL’s Batch rollout now depends on validators adopting the emergency 3.4.1 release.

The Security Fix Is Not Public Yet

One unusual detail is that the source code for the security-sensitive fixes has not yet been published.

XRPL says the code will be released later together with a retrospective explaining the issue in more detail. That means the full severity and technical impact of the vulnerability are not yet public.

There is also no indication in the release notes that XRP funds were stolen or that the XRP Ledger itself suffered a live exploit.

The update instead appears to be preventative, aimed at fixing protocol-level issues before the new Batch functionality becomes active.

The Batch upgrade itself is designed to let developers package multiple transactions together, including atomic operations where every step succeeds or the entire batch fails.