In a concerning revelation, RippleX engineer Mayukha Vadari has highlighted escalating security risks in the domain of software during the age of artificial intelligence. This comes after XRP Ledger developers made public a critical vulnerability that could have potentially led to the generation of trillions of XRP—an issue underscoring the fragility of the digital asset’s ecosystem.
Vulnerability Existed Unnoticed for a Decade
This security flaw had been embedded within the XRP Ledger for nearly ten years, posing a significant threat to the network’s fixed supply of 100 billion XRP. On September 21, the AI-based security system Veria AI, developed by Veria Labs, identified the vulnerability. Researchers swiftly reported the issue through the XRP Ledger’s official bug bounty program the following day.
Mayukha Vadari remarked, “With AI, the landscape has changed; it’s no longer feasible to quietly insert a pivotal bug fix into the regular open release process, as it can now be rapidly reverse-engineered.”
Veria Labs noted that the flaw could have allowed a single transaction to create an astounding 18.45 trillion XRP, vastly exceeding the initial total supply by 184 times. These newly created XRPs could have been spent and moved across various cryptocurrency exchanges, leading to broad economic repercussions.
Root of the Issue Tied to Decentralized Exchange Operations
A technical analysis revealed the problem originated from a piece of code implemented in 2015. The flaw was linked to a method concerning payment calculations within the network’s decentralized exchange setup, affecting multiple offers processed simultaneously. Under particular conditions, attackers could generate hundreds of special transaction offers containing exorbitant XRP values.
If processed collectively, this could cause an overflow in the system’s 64-bit integer calculations. Instead of being rejected, a notably reduced value was computed, allowing the selling party to receive full XRP payments while the buyer would be charged merely a fraction of the total worth. Moreover, a similar calculation flaw was found in the native mechanism that was supposed to prevent gratuitous XRP creation.
XRPL developers confirmed that they found no evidence of this vulnerability being exploited on the public network.
Emergency Patch Released with a Temporary Hold on Source Code
Following the disclosure, the XRP Ledger development team quickly released the xrpld 3.4.1 emergency update on September 25. Nonetheless, they chose not to share the source code including the security fixes immediately. This move aimed to prevent potential attackers from analyzing the patch to swiftly deduce specifics of the vulnerability.
This strategy sparked debate within the cryptocurrency community regarding adherence to open source principles. Critics focused on whether distributing binary files without concurrently releasing the source code aligns with the network’s open source ethos.
During the vulnerability notification, the market capitalization of XRP was roughly estimated at $94 billion. If exploited effectively, the issue could have spiraled beyond technical bounds, potentially leading to far-reaching market consequences.



