AI agent discovers decade-old XRP Ledger bug that could have minted 18 trillion tokens

Vulnerability patched within days; no funds lost and no exploitation found, developers say

By LineZotpaper
Published
Read Time2 min
An AI-powered security system has uncovered a critical vulnerability in the XRP Ledger (XRPL) that could have allowed an attacker to create roughly 18 trillion XRP tokens, threatening the cryptocurrency's $94 billion market capitalisation. The bug, which survived more than a decade of security reviews and audits, was reported on September 22 and patched three days later, with no evidence of exploitation.

Security firm Veria Labs disclosed that its AI system identified two interconnected flaws in the rippled software that underpins the XRP Ledger. The first was an integer overflow in the payment engine that could cause the system to miscalculate amounts in a trade, allowing a buyer to pay only a fraction of the actual cost while the seller received full payment. The second vulnerability affected the network's supply-protection mechanism, which relied on the same flawed arithmetic and could fail to detect that new XRP had been created.

Veria founder Cayden Liao said the attack would have required only a few hundred XRP in refundable reserves and ordinary transaction fees, with the attacker needing to prepare hundreds of accounts and trading offers before submitting the payment. The underlying payment-engine code dates to 2015, while the affected supply safeguard was introduced in 2017.

Despite more than a dozen audits and security contests since 2024, including a competition with a $550,000 prize pool and bug bounty programs distributing over $1 million, the combined vulnerability remained undetected until Veria's AI system assembled a working exploit and demonstrated the problem on a local network.

RippleX confirmed on October 9 that no unauthorized XRP was created, no funds were lost, and investigators found no evidence of exploitation on public networks. The disclosure notes that the fix was applied within three days of reporting.

§

Analysis

Why This Matters

  • XRP holders could have faced catastrophic dilution of their holdings, potentially wiping out $94 billion in market value
  • The discovery highlights the limits of traditional security audits, even after years of scrutiny and significant bounty rewards
  • AI-driven security tools may become increasingly important for finding critical vulnerabilities in blockchain infrastructure

Background

The XRP Ledger is a decentralised blockchain designed for fast, low-cost payments. Its native token, XRP, has a fixed supply of 100 billion tokens, a feature central to its value proposition. The network has undergone extensive security reviews, including professional audits and public bug bounty programs, yet this bug evaded detection for nearly a decade. Veria Labs is a security firm that develops AI agents for automated vulnerability discovery.

Key Perspectives

RippleX and XRPL developers: The vulnerability was patched within three days, no exploitation occurred, and the fix was applied without harm to users or the network. Veria Labs: The discovery demonstrates that AI systems can identify complex, multi-step exploits that human auditors miss, potentially raising the bar for blockchain security. Critics and skeptics: Some may question whether the bug was truly exploitable or whether AI-driven disclosure creates unnecessary panic. The fact that it survived multiple audits also raises questions about the effectiveness of traditional security practices.

What to Watch

  • Whether other blockchain networks adopt similar AI-driven security audits
  • Any regulatory or community response regarding XRPL governance after developers bypassed established procedures to apply the emergency fix
  • Further disclosures from Veria Labs about other vulnerabilities found by its AI systems

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe