Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

AI Discovers Critical Flaw in XRP Ledger That Could Generate 18 Trillion Tokens

Security researchers using AI identified a decade-old vulnerability in the XRP Ledger that could have created trillions of XRP tokens. The flaw was patched within days, with no evidence of exploitation found.
1 hour ago 11 views
AI Discovers Critical Flaw in XRP Ledger That Could Generate 18 Trillion Tokens

An artificial intelligence security system uncovered a critical vulnerability in the XRP Ledger that could have enabled the creation of approximately 18 trillion XRP tokens through a single payment transaction. According to security firm Veria Labs, this amount would represent roughly 180 times the cryptocurrency's original 100 billion token supply.

The vulnerability was reported on September 22 and patched three days later. RippleX confirmed that no unauthorized XRP was created, no funds were lost, and investigators found no evidence of exploitation on public networks. The incident was publicly disclosed on October 9.

How the Vulnerability Worked

Veria's AI-powered security system identified two interconnected flaws in rippled, the software underlying XRPL. The first involved an integer overflow in the payment engine, where specially constructed trading offers could cause the system to miscalculate the amount a buyer owed.

Under this exploit, sellers would receive their full XRP payments while buyers would be charged only a fraction of the actual amount. The difference would effectively create XRP that had never existed. A second vulnerability affected the network's supply-protection mechanism, which relied on the same flawed arithmetic and could fail to recognize newly created XRP.

The underlying payment-engine code dates to 2015, while the affected supply safeguard was introduced in 2017. The attack would have required an attacker to prepare hundreds of accounts and trading offers, needing only a few hundred XRP in largely refundable reserves and ordinary transaction fees.

Security History and Detection

The XRPL codebase had undergone more than a dozen audits and security contests since 2024, including one competition with a $550,000 prize pool. Its bug bounty programs had distributed more than $1 million. Despite these efforts, the combined vulnerability remained undetected until Veria's AI system identified it, assembled a working exploit, and demonstrated the problem on a local network.

Veria received a $250,000 bounty, the program's maximum. This marked the largest known reward for a vulnerability discovered entirely by an AI agent.

Emergency Protocol Change

The severity of the discovery forced XRPL developers to deploy a protocol-changing fix without following the network's established amendment process. Ordinarily, changes require support from more than 80% of trusted validators for two consecutive weeks before activation.

Developers determined that following this procedure would leave the vulnerability exposed during the voting period. Since the XRPL software is open source, publishing the fix could also reveal the exploit to potential attackers before protection became effective.

Instead, RippleX, the XRP Ledger Foundation, and validators coordinated an emergency upgrade that activated the protection immediately on servers running version 3.4.1. The patch was initially distributed as binaries, temporarily withholding source code to limit reverse-engineering risks. This marked the first deliberate bypass of the amendment activation process for a transaction-processing change in more than a decade.

More than 80% of validators on the default trusted-validator list had upgraded by September 25.

Future Security Measures

The incident has prompted RippleX to reassess how it protects critical infrastructure, particularly older software that has survived years of conventional security reviews. Plans include expanding AI-assisted vulnerability discovery, strengthening adversarial testing, and increasing scrutiny of legacy components including the payment engine and consensus mechanisms.

The organization also plans to accelerate formal verification, a mathematical technique that proves whether software meets specific security properties. A new procedural requirement mandates that security findings previously classified as resolved must now be retested against release candidates before being formally closed.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.