AI Found an XRP Ledger Flaw That Could Have Broken Its Fixed Supply
• October 11, 2026 7:54 am • CommentsA flaw buried in the XRP Ledger for roughly a decade could have done the one thing a fixed-supply cryptocurrency is never supposed to allow: create new, spendable coins out of thin air.
The good news is just as important as the scary part. The bug was found before attackers used it, developers deployed an emergency fix, and RippleX says investigators found no evidence that unauthorized XRP was created on public networks.
CryptoSlate reports that an AI-powered security system operated by Veria Labs found two connected weaknesses in the XRP Ledger payment engine. Used together, they could have let a specially prepared transaction pay a seller the full amount while charging the buyer only a fraction of what was owed.
The mismatch would effectively mint XRP outside the network’s fixed supply.
Veria reported the issue on September 22, and XRPL engineers reproduced it before coordinating the fix. The payment-engine code at the center of the failure dated to 2015.
A related supply safeguard introduced in 2017 used the same arithmetic, allowing the two weaknesses to reinforce each other and conceal the unauthorized increase from the mechanism designed to stop exactly that outcome.
The researchers said an attacker would have needed hundreds of prepared accounts and offers, but only a modest amount of XRP for refundable reserves and ordinary transaction fees, making the attack economically practical despite its technical complexity.
RippleX confirmed that the newly created balance could have been spent in later transactions, turning an accounting error into a direct supply breach.
A theoretical 18 trillion XRP problem
Veria’s researchers estimated that one exploit transaction could have produced roughly 18 trillion XRP, about 180 times the original 100 billion-token supply. That does not mean 18 trillion XRP ever entered circulation.
It describes the upper-end consequence of the bug before it was patched.
The vulnerability involved integer arithmetic in code that dates to 2015, plus a later supply-protection mechanism that relied on the same flawed calculations. That combination is why the issue survived ordinary reviews: each safeguard could appear reasonable on its own while failing under a carefully engineered sequence of offers and payments.
XRPL 3.4.1 is now the new minimum software version with the recent amendments activated and the vulnerability report has been published.
Through the bug bounty program, an issue was reported on September 22 that could have led to the creation of additional XRP via an integer… https://t.co/DOEYCbCmWI
— Vet (@Vet_X0) October 10, 2026
Why developers bypassed the usual amendment process
XRPL normally requires more than 80% support from trusted validators for two straight weeks before a transaction-processing amendment activates. In this case, waiting through the normal public process would have advertised the weakness while leaving it exploitable.
Developers instead coordinated a rapid upgrade to version 3.4.1 and initially distributed binaries without immediately publishing the vulnerable code path. More than 80% of validators on the default trusted list had reportedly upgraded by September 25.
The public disclosure followed after the protection was broadly in place.
CoinDesk likewise described the flaw as a fixed-supply threat and emphasized that the affected payment logic had been present for years. That matters because XRP’s supply discipline is part of the basic economic promise investors rely on.
A bug capable of violating it reaches the asset’s credibility.
The affected logic was old enough to have passed through years of normal review, which makes the discovery more consequential than a routine patch. It also shows why fixed-supply claims ultimately depend on software enforcing them correctly.
The report arrived only after validators had moved to the protected release, limiting the window in which public technical details could help an attacker reverse-engineer the flaw and test it against unprotected production servers.
That sequencing mattered because the open-source patch itself could have revealed the route to exploitation before enough validators were protected, leaving the network exposed during the normal two-week amendment voting period.
The coordinated rollout traded a short period of operational risk for protection against counterfeit XRP entering circulation, and the network stayed intact.
Security remains our top priority for preserving trust in the XRP Ledger (XRPL). Sharing a few thoughts following yesterday’s disclosure of the critical payments engine vulnerability reported by Veria AI.
First, this was a serious vulnerability, and we don’t take that lightly.…
— J. Ayo Akinyele (@ja_akinyele) October 10, 2026
The larger lesson for XRP
XRP was the fifth-largest cryptocurrency by market value at the time of the disclosure, with a market capitalization around $88 billion. The fact that a flaw this old remained hidden after repeated audits is a reminder that mature code is not automatically safe code.
It is also a strong argument for using AI defensively. Veria’s system did more than flag suspicious code; it assembled the conditions needed to reproduce the failure on a local network.
RippleX engineers then independently verified the exploit and the ability to spend the newly created XRP.
The response appears to have protected holders this time. No public-network exploitation has been identified, no unauthorized XRP was found, and the minimum supported software version now includes the fix.
The incident will likely reshape how XRPL reviews older transaction logic. RippleX has said it plans to expand AI-assisted testing, adversarial analysis and formal verification.
That is the right takeaway. The emergency patch prevented a theoretical supply catastrophe, but the real win will come if this discovery makes the network harder to surprise the next time.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
