AI discovers XRP Ledger flaw that could mint 18 trillion tokens and put $94 billion market at risk
The decade-old vulnerability escaped years of safety critiques and compelled XRP Ledger
(XRPL) builders to bypass established governance procedures.
An AI agent uncovered a decade-old XRPL bug that could create trillions of XRP, prompting an emergency repair.
The vulnerability could have let an attacker generate about 18 trillion XRP by way of a single fee transaction, roughly 180 occasions the cryptocurrency’s authentic 100 billion token provide, in response to safety agency Veria Labs.
Veria founder Cayden Liao said the flaw probably threatened XRP’s $94 billion market capitalization by undermining the cryptocurrency’s fastened provide.
The vulnerability was reported on Sept. 22 and patched three days later. RippleX later confirmed that no unauthorized XRP was created, no funds have been misplaced, and investigators discovered no proof of exploitation on public networks. The incident was publicly disclosed on Oct. 9.
AI uncovers two interconnected flaws that survived a decade of audits
The discovery emerged from Veria’s AI-powered safety system, which analyzed rippled, the software program underpinning XRPL, and recognized two weaknesses that could be mixed to bypass its financial safeguards.
The first concerned an integer overflow within the fee engine, the place intentionally constructed buying and selling gives could trigger the system to miscalculate the quantity a purchaser owed.
Under the exploit, sellers would obtain their full XRP funds whereas the client could be charged solely a fraction of the particular quantity. The distinction would successfully create XRP that had by no means existed.
A second vulnerability affected the community’s supply-protection mechanism. Because it relied on the identical flawed arithmetic, it could fail to acknowledge that new XRP had been created.
The attacker would want to organize a whole lot of accounts and buying and selling gives earlier than submitting the fee. According to the official vulnerability report, the assault required only some hundred XRP in largely refundable reserves and extraordinary transaction charges.

The underlying payment-engine code dates to 2015, whereas the affected provide safeguard was launched in 2017.
That longevity is especially vital given the community’s safety historical past.
Liao mentioned the XRPL codebase had undergone greater than a dozen audits and safety contests since 2024, together with one competitors with a $550,000 prize pool. Its bug bounty packages had additionally distributed greater than $1 million.
Despite these efforts, the mixed vulnerability remained undetected till Veria’s AI system recognized it, assembled a working exploit, and demonstrated the issue on a neighborhood community.
RippleX engineers independently reproduced the exploit and confirmed that the newly generated XRP could be spent in subsequent transactions.
Veria obtained a $250,000 bounty, this system’s most. Liao described it as the most important recognized reward for a vulnerability found fully by an AI agent.
Emergency repair bypasses decade-old governance procedures
The severity of the invention compelled XRPL builders into an uncommon determination: deploy a protocol-changing repair with out ready for the community’s established modification course of.
Ordinarily, adjustments to transaction-processing guidelines require assist from greater than 80% of trusted validators for 2 consecutive weeks earlier than activation.
However, builders decided that following this process would go away the vulnerability uncovered whereas the community voted on its restore.
Because XRPL software program is open supply, publishing the repair could additionally reveal the exploit to potential attackers earlier than the safety turned efficient.
Instead, RippleX, the XRP Ledger Foundation and validators coordinated an emergency improve that activated the safety instantly on servers operating model 3.4.1.
The patch was initially distributed as binaries, briefly withholding its supply code to restrict the risk of attackers reverse-engineering the vulnerability throughout deployment.
According to the disclosure, this marked the primary deliberate bypass of the modification activation course of for a transaction-processing change in additional than a decade.
The strategy carried its personal hazard. Servers operating completely different variations could disagree on whether or not an exploit transaction was legitimate, probably disrupting consensus or halting the community.
Developers nonetheless concluded that a brief community interruption was preferable to letting counterfeit XRP enter circulation.
More than 80% of validators on the default trusted-validator listing had upgraded by Sept. 25, considerably lowering that risk.
XRPL Foundation contributor Vet said the coordinated response preserved community integrity and established model 3.4.1 as the brand new minimal software program requirement following the activation of separate Batch-related amendments on Oct. 9.
RippleX turns to AI and formal verification after safety scare
The incident has prompted RippleX to reassess the way it protects important infrastructure, significantly older software program that has survived years of typical safety critiques.
J. Ayo Akinyele, RippleX’s head of engineering, acknowledged that the vulnerability demonstrated the necessity to revisit longstanding assumptions concerning the community’s design.
He outlined plans to broaden AI-assisted vulnerability discovery, strengthen adversarial testing and enhance scrutiny of legacy parts, together with the fee engine, consensus mechanisms and peer-to-peer networking.
The group additionally plans to speed up formal verification, a mathematical approach that proves whether or not software program meets particular safety properties.
That work will construct on current verification efforts involving XRPL’s Lending Protocol and Single Asset Vault, alongside collaboration with CommonPrefix and the XRP Ledger Foundation.
Akinyele mentioned AI is essentially accelerating vulnerability discovery, placing strain on builders to seek out weaknesses earlier than malicious actors deploy related instruments.
Vet echoed that concern, warning that more and more succesful AI methods could make beforehand obscure vulnerabilities simpler to take advantage of.
The October 9 disclosure additionally launched a selected procedural change: safety findings beforehand categorised as resolved should now be retested in opposition to launch candidates earlier than being formally closed.
The put up AI discovers XRP Ledger flaw that could mint 18 trillion tokens and put $94 billion market at risk appeared first on CryptoSlate.
