Breaking
ESPoland reunites its security services after warning of a possible attack against its prime minister and deputy prime ministerCNA murder case was reported at Fengyuan Snack Shop in Taichung. A drunkard beat the man at the table next to him to death and was taken into custody.RUSobyanin announced a new attempt by the Armed Forces of Ukraine to attack MoscowTRBREAKING NEWS: What is the new regulation on the sale of cigarettes to people under the age of 18? How will age verification be done?CNWTT Grand Slam" is almost! Lin Yunru fought fiercely for 7 games and lost to the champion Matsushima Terukora, finishing second and tied for the best.TRLast minute... Horror in the water! Immigrant boat sank: 109 deaths, including 15 childrenRUThree people died as a result of a traffic accident in the Orenburg regionBRCírio de Nazaré 2026: Procession runs along Boulevard Castilhos FrançaBROur Lady of Aparecida Day: check the timetable for masses and celebrations in Juiz de ForaKRSeoul raises travel alert, urges citizens to leave Saudi ArabiaESPoland reunites its security services after warning of a possible attack against its prime minister and deputy prime ministerCNA murder case was reported at Fengyuan Snack Shop in Taichung. A drunkard beat the man at the table next to him to death and was taken into custody.RUSobyanin announced a new attempt by the Armed Forces of Ukraine to attack MoscowTRBREAKING NEWS: What is the new regulation on the sale of cigarettes to people under the age of 18? How will age verification be done?CNWTT Grand Slam" is almost! Lin Yunru fought fiercely for 7 games and lost to the champion Matsushima Terukora, finishing second and tied for the best.TRLast minute... Horror in the water! Immigrant boat sank: 109 deaths, including 15 childrenRUThree people died as a result of a traffic accident in the Orenburg regionBRCírio de Nazaré 2026: Procession runs along Boulevard Castilhos FrançaBROur Lady of Aparecida Day: check the timetable for masses and celebrations in Juiz de ForaKRSeoul raises travel alert, urges citizens to leave Saudi Arabia
BackAI discovers XRP Ledger flaw that could mint 18 trillion tokens and put $94 billion market at risk
AI discovers XRP Ledger flaw that could mint 18 trillion tokens and put $94 billion market at risk
Developing
CryptoSlate1 hour agoCrypto4 min read

AI discovers XRP Ledger flaw that could mint 18 trillion tokens and put $94 billion market at risk

An emergency fix bypassed standard governance procedures after security firm Veria Labs discovered a flaw surviving a decade of audits.

Quick Look

  • An AI agent uncovered a decade-old vulnerability in the XRP Ledger that could have created 18 trillion XRP.
  • RippleX and validators deployed an emergency fix, bypassing standard governance procedures to prevent exploitation.

AI-generated summary

Why It Matters

The underlying payment-engine code dated to 2015, while the affected supply safeguard was introduced in 2017. The vulnerability survived over a decade of security audits.

Font size

The decade-old vulnerability escaped years of security reviews and forced XRP Ledger

(XRPL) developers to bypass established governance procedures.

An AI agent uncovered a decade-old XRPL bug that could create trillions of XRP, prompting an emergency fix.

The vulnerability could have let an attacker generate about 18 trillion XRP through a single payment transaction, roughly 180 times the cryptocurrency's original 100 billion token supply, according to security firm Veria Labs.

Veria founder Cayden Liao said the flaw potentially threatened XRP's $94 billion market capitalization by undermining the cryptocurrency's fixed supply.

The vulnerability was reported on Sept. 22 and patched three days later. RippleX later confirmed that no unauthorized XRP was created, no funds were lost, and investigators found no evidence of exploitation on public networks. The incident was publicly disclosed on Oct. 9.

AI uncovers two interconnected flaws that survived a decade of audits

The discovery emerged from Veria's AI-powered security system, which analyzed rippled, the software underpinning XRPL, and identified two weaknesses that could be combined to bypass its monetary safeguards.

The first involved an integer overflow in the payment engine, where deliberately constructed trading offers could cause the system to miscalculate the amount a buyer owed.

Under the exploit, sellers would receive their full XRP payments while the buyer would be charged only a fraction of the actual amount. The difference would effectively create XRP that had never existed.

A second vulnerability affected the network's supply-protection mechanism. Because it relied on the same flawed arithmetic, it could fail to recognize that new XRP had been created.

The attacker would need to prepare hundreds of accounts and trading offers before submitting the payment. According to the official vulnerability report, the attack required only a few hundred XRP in largely refundable reserves and ordinary transaction fees.

The underlying payment-engine code dates to 2015, while the affected supply safeguard was introduced in 2017.

That longevity is particularly significant given the network's security history.

Liao said the XRPL codebase had undergone more than a dozen audits and security contests since 2024, including one competition with a $550,000 prize pool. Its bug bounty programs had also distributed more than $1 million.

Despite those efforts, the combined vulnerability remained undetected until Veria's AI system identified it, assembled a working exploit, and demonstrated the problem on a local network.

RippleX engineers independently reproduced the exploit and confirmed that the newly generated XRP could be spent in subsequent transactions.

Veria received a $250,000 bounty, the program's maximum. Liao described it as the largest known reward for a vulnerability discovered entirely by an AI agent.

Emergency fix bypasses decade-old governance procedures

The severity of the discovery forced XRPL developers into an unusual decision: deploy a protocol-changing fix without waiting for the network's established amendment process.

Ordinarily, changes to transaction-processing rules require support from more than 80% of trusted validators for two consecutive weeks before activation.

However, developers determined that following this procedure would leave the vulnerability exposed while the network voted on its repair.

Because XRPL software is open source, publishing the fix could also reveal the exploit to potential attackers before the protection became effective.

Instead, RippleX, the XRP Ledger Foundation and validators coordinated an emergency upgrade that activated the protection immediately on servers running version 3.4.1.

The patch was initially distributed as binaries, temporarily withholding its source code to limit the risk of attackers reverse-engineering the vulnerability during deployment.

According to the disclosure, this marked the first deliberate bypass of the amendment activation process for a transaction-processing change in more than a decade.

The approach carried its own danger. Servers running different versions could disagree on whether an exploit transaction was valid, potentially disrupting consensus or halting the network.

Developers nevertheless concluded that a temporary network interruption was preferable to letting counterfeit XRP enter circulation.

More than 80% of validators on the default trusted-validator list had upgraded by Sept. 25, substantially reducing that risk.

XRPL Foundation contributor Vet said the coordinated response preserved network integrity and established version 3.4.1 as the new minimum software requirement following the activation of separate Batch-related amendments on Oct. 9.

RippleX turns to AI and formal verification after security scare

The incident has prompted RippleX to reassess how it protects critical infrastructure, particularly older software that has survived years of conventional security reviews.

J. Ayo Akinyele, RippleX's head of engineering, acknowledged that the vulnerability demonstrated the need to revisit longstanding assumptions about the network's design.

He outlined plans to expand AI-assisted vulnerability discovery, strengthen adversarial testing and increase scrutiny of legacy components, including the payment engine, consensus mechanisms and peer-to-peer networking.

The organization also plans to accelerate formal verification, a mathematical technique that proves whether software meets specific security properties.

That work will build on existing verification efforts involving XRPL's Lending Protocol and Single Asset Vault, alongside collaboration with CommonPrefix and the XRP Ledger Foundation.

Akinyele said AI is fundamentally accelerating vulnerability discovery, putting pressure on developers to find weaknesses before malicious actors deploy similar tools.

Vet echoed that concern, warning that increasingly capable AI systems could make previously obscure vulnerabilities easier to exploit.

The October 9 disclosure also introduced a specific procedural change: security findings previously classified as resolved must now be retested against release candidates before being formally closed.

What to Watch

AI outlook — possibilities, not facts

  • RippleX will expand AI-assisted vulnerability discovery and formal verification.

    Very likely · Within months

Open Questions

  • How many other legacy blockchain components contain undiscovered AI-detectable flaws?
  • Will future emergency updates bypass governance permanently in crisis scenarios?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

US plans to seize $1B in crypto linked to Iran this week: Scott Bessent
Developing·

US plans to seize $1B in crypto linked to Iran this week: Scott Bessent

US Treasury Secretary Scott Bessent stated the US plans to seize approximately $1 billion in cryptocurrency this week as part of sanctions on Iran, citing efforts to economically isolate the country amid its ongoing military conflict that began in February. He referenced prior seizures and noted coordination with stablecoin issuers like Tether, which reported freezing $550 million in USDT in 2026.

Cointelegraph
1 min read
More on this topicxrpl