AI system discovers decade-old XRP Ledger bug allowing 18 trillion token mint
An artificial intelligence security tool uncovered a decade-old bug in the XRP Ledger that could have let an attacker mint roughly 18 trillion XRP in a single transaction, more than 180 times the cryptocurrency’s original 100 billion token supply. RippleX patched the flaw within days and is now expanding AI-driven testing to catch similar weaknesses in core blockchain infrastructure.
- An AI system built by Veria Labs combined two separate flaws to craft a working exploit on a test network.
- RippleX confirmed no unauthorized XRP was created and no funds were lost on the public network.
- Veria Labs collected a $250,000 bounty, the maximum payout under the program, for the discovery.
- 18T XRP amount an attacker could mint, 180x the 100B original supply
- $94B XRP market capitalization the bug put at risk
- $250K bounty Veria Labs received, the program’s maximum payout
- 3 days time from report to patch, Sept. 22 to Sept. 25
An AI-powered security system has exposed a vulnerability in the XRP Ledger that sat undetected for roughly a decade, according to CryptoSlate. The flaw could have let an attacker generate approximately 18 trillion XRP through a single payment transaction, security firm Veria Labs said.
Veria Labs founder Cayden Liao said the vulnerability threatened XRP’s $94 billion market capitalization by undermining its fixed-supply model. The bug was reported Sept. 22 and patched three days later, with RippleX disclosing the episode publicly on Friday (October 9).
RippleX later confirmed that no unauthorized XRP was created, no funds were lost, and investigators found no evidence of exploitation on public networks.
An AI agent found two flaws that survived years of audits
The discovery emerged from Veria Labs’ AI-powered security system, which analyzed rippled, the core software running the XRP Ledger. The system identified two separate weaknesses that, combined, could bypass the network’s built-in protections against inflating its token supply.
The first was an integer overflow in XRPL’s payment engine. Deliberately constructed trading offers could cause the system to miscalculate what a buyer owed, so a seller would receive a full XRP payment while the buyer was charged only a fraction of the real amount, effectively creating XRP that never existed.
A second flaw affected the network’s supply-protection mechanism, which relied on the same flawed arithmetic and so failed to flag the newly created tokens. Pulling off the attack would have required preparing hundreds of accounts and trading offers before submitting a single payment, though the official vulnerability report said the attack itself needed only a few hundred XRP in largely refundable reserves plus ordinary transaction fees.
The underlying payment-engine code dates to 2015, and the affected supply safeguard was introduced in 2017. Liao said the XRPL codebase had undergone more than a dozen audits and security contests since 2024, including one competition with a $550,000 prize pool, while its bug bounty programs have paid out more than $1 million in total.
RippleX engineers independently reproduced the exploit and confirmed the newly minted
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
