Altcoins · News

XRP Ledger patches bug that could have minted 180 times its supply

An overflow bug in the XRP Ledger's payment engine, present since 2015, could have minted 18 trillion XRP, 180 times its supply, before being patched by RippleX.

XRP Ledger patches bug that could have minted 180 times its supply

About 18 trillion XRP$1.41▲0.31% could have been created in a single transaction because of an overflow bug in the XRP Ledger’s payment engine, according to The Block’s report. The flaw could have pushed spendable XRP beyond the network’s 100 billion cap, which was established when all 100 billion tokens were created at the ledger’s launch in 2012.

RippleX fixed the issue on Sept. 25 through xrpld version 3.4.1, three days after AI security startup Veria Labs reported it on Sept. 22. The patch was deployed without the XRP Ledger’s usual amendment vote because of the severity of the vulnerability.

The arithmetic is stark: 18 trillion XRP divided by the 100 billion XRP supply equals 180 times the entire launch supply. That is the potential mint described in the reporting, not a confirmed issuance. The available account establishes that the bug could have been exploited; it does not establish that an attacker actually created XRP.

The flaw had been present in the code since 2015, making the exposure roughly 11 years old when it was fixed. Veria Labs received the program’s maximum $250,000 bounty. Cayden Liao, a security co-founder at Veria Labs, said the vulnerability chained together two bugs that would have been low severity individually, which he suspected was why it went undetected.

The response was fast once the report arrived. RippleX shipped the fix three days later, and more than 80% of validators on the default Unique Node List were running it on Sept. 25.

The protection did not switch on at one network-wide moment. The fix took effect as each server upgraded, a change described as the first such deployment in more than 10 years of amendments for the XRP Ledger. The source code for version 3.4.1 was published about two weeks after the binaries, according to the report.

For validators, the immediate consequence was operational: upgrading to version 3.4.1 was the step that activated the protection on each server. For XRP holders, the relevant trade-off was supply integrity. The ledger’s 100 billion cap could have been exceeded in one transaction before the patch reached the network’s servers; after an upgrade, that server received the fix.

RippleX engineer Mayukha Vadari said, “AI has changed things. You can’t sneak a critical bug patch into a routine public release process, it’ll get spotted and reverse-engineered immediately.” J. Ayo Akinyele, RippleX’s Head of Engineering, said, “AI is fundamentally changing how quickly vulnerabilities can be discovered.” Veria’s Liao called the $250,000 payment, to the firm’s knowledge, the largest ever paid for a vulnerability found entirely by an AI agent.

The same reporting places the disclosure alongside two other AI-assisted security incidents: a Coldcard wallet bug linked to the theft of at least 1,367 BTC$83,602.00▲0.71%, and Core Lightning vulnerabilities that forced Bitcoin node operators to disconnect. Those events are listed as prior incidents since July, though the supplied information does not provide a comparable XRP Ledger exploit.

The desk’s read is narrower and more serious than the patch timeline: the fix removed the immediate minting path, but a critical flaw surviving from 2015 raises a documented question about how thoroughly historical code has been audited. The fact sheet identifies no formal XRP Ledger-wide audit for similar undiscovered bugs, and it gives no details on whether one is underway.

XRP was priced at $1.41 with a 0.8% 24-hour gain on CoinGecko’s market listing. That move provides market context, not evidence that traders had priced in the vulnerability or the patch.

ai ripple security veria labs xrp xrp ledger
Nadia Rahman

Nadia Rahman

Markets Editor · 9 years covering crypto · Author page

Nadia Rahman is CoinScoop's Markets Editor. She covers Bitcoin, macro liquidity and the spot-ETF complex, and previously reported on rates and FX for a global newswire.

Disclosure: This article is independent journalism and is for information only — it is not financial advice. CoinScoop is reader-supported and may earn a commission from some links. Read our disclosure policy →