Security firm Veria Labs disclosed that its AI system identified two interconnected flaws in the rippled software that underpins the XRP Ledger. The first was an integer overflow in the payment engine that could cause the system to miscalculate amounts in a trade, allowing a buyer to pay only a fraction of the actual cost while the seller received full payment. The second vulnerability affected the network's supply-protection mechanism, which relied on the same flawed arithmetic and could fail to detect that new XRP had been created.
Veria founder Cayden Liao said the attack would have required only a few hundred XRP in refundable reserves and ordinary transaction fees, with the attacker needing to prepare hundreds of accounts and trading offers before submitting the payment. The underlying payment-engine code dates to 2015, while the affected supply safeguard was introduced in 2017.
Despite more than a dozen audits and security contests since 2024, including a competition with a $550,000 prize pool and bug bounty programs distributing over $1 million, the combined vulnerability remained undetected until Veria's AI system assembled a working exploit and demonstrated the problem on a local network.
RippleX confirmed on October 9 that no unauthorized XRP was created, no funds were lost, and investigators found no evidence of exploitation on public networks. The disclosure notes that the fix was applied within three days of reporting.