Skip to content
Latest
STOX.NEWS
In focus

An XRP Ledger security bug could have created 18.45 trillion XRP

Image supplied by The Cryptonomist.
Advertisement
Demo creative for ADG7 Article top (728x90)

An XRP Ledger security bug discovered on September 21, 2026, could have let attackers create 18.45 trillion XRP in a single transaction—more than 184 times the token’s fixed supply. Developers patched the decade-old flaw on September 25, 2026, and found no evidence of exploitation on public networks.

Key takeaways

The flaw originated in payment-calculation code added in 2015.

Veria AI helped uncover a way to create spendable XRP.

The emergency patch shipped without public source code.

RippleX engineer Mayukha Vadari warned that AI makes hidden security patches easier to reverse engineer.

According to U.Today, the disclosure prompted Mayukha Vadari , an engineer at RippleX, to warn that artificial intelligence is changing how developers must handle critical fixes. The team’s decision to distribute compiled software while withholding the patch’s source code also drew criticism over the network’s open-source commitments.

CoinDesk reported that RippleX engineers reproduced the attack on a standalone server and verified that the XRP it created could fund a subsequent transaction. That demonstration was separate from the public network, where developers found no evidence of exploitation.

How the XRP Ledger security bug was discovered

Veria AI , a security system developed by Veria Labs, detected the vulnerability on September 21, 2026. Researchers submitted it through the XRP Ledger bug bounty program the following day.

CoinDesk identified researcher Cayden Liao alongside Veria AI in the discovery. The flaw traced to code introduced in 2015 , leaving it present for more than a decade before detection.

According to Veria Labs, a single transaction exploiting the vulnerability could have generated about 18.45 trillion XRP . That exceeded the cryptocurrency’s 100 billion XRP fixed supply by more than 184 times. All 100 billion tokens were created at the ledger’s launch in 2012; its software is designed to prevent further issuance.

How a payment calculation could create XRP

The vulnerability was an integer overflow in the ledger’s payment engine when it processed multiple trading offers through its built-in decentralized exchange. Under certain conditions, the total payment exceeded what the system’s 64-bit calculations could handle.

An attacker could have opened hundreds of accounts, each offering a tiny quantity of another token for an unusually large XRP payment. One payment buying all those offers would push the combined XRP amount beyond the calculation’s limit.

Instead of rejecting the transaction, the software would calculate a much smaller total. The selling accounts would receive their full XRP amounts while the buying account paid almost nothing.

The safeguard checking for newly created XRP relied on the same incorrect total. A separate account-receipt limit would also fail to stop the attack because the XRP was distributed across hundreds of accounts. CoinDesk reported that the setup required only a few hundred XRP, most of it recoverable, plus transaction fees.

The resulting tokens could have been spent or transferred to cryptocurrency exchanges. Researchers estimated XRP’s market capitalization at around $94 billion when filing the report and believed the flaw threatened that entire value.

An emergency fix without public source code

Developers released xrpld 3.4.1 on September 25, 2026, to fix the vulnerability. They distributed binaries but withheld the security patch’s source code.

The release initially did not identify what it repaired, CoinDesk reported. Withholding the code drew criticism over whether that approach was consistent with XRPL’s open-source nature.

Vadari’s warning about AI and security patches

Vadari warned that AI makes it harder to quietly include critical fixes in a normal public software release. Her concern centered on rapid detection and reverse engineering of the patch.

“Things have changed with AI. You can’t just sneak in a critical bug patch in a regular public release process, because you’re going to get caught and reverse engineered right away,” Vadari said in a post on X.

In this case, an AI-based security system helped discover a flaw that had persisted since 2015, and RippleX confirmed the exploit in a standalone-server test.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Advertisement
Demo creative for ADG8 Article body (336x280)

Companies named

More on this