Veria Labs says its AI found XRP Ledger bug that could have minted 18 trillion XRP

Editorial illustration: A microscope casts blue light onto three connected transparent blocks. An XRP symbol rests on the upper block, and a small orange glow highlights a branching crack near the central junction.

In brief

  • Veria Labs says its AI found two rippled flaws that could mint about 18 trillion XRP.
  • RippleX said no unauthorized XRP was created and found no evidence of public-network exploitation.
  • Bug reported Sept. 22, patched three days later and disclosed Oct. 9.
  • Emergency upgrade skipped the usual validator vote, activating immediately on version 3.4.1.
  • Veria said it received a $250,000 bounty, the program's maximum.

How the exploit worked

According to Veria, 18 trillion XRP would be roughly 180 times XRP's original 100 billion token supply. Veria founder Cayden Liao said the flaw potentially threatened XRP's $94 billion market cap by undermining its fixed supply. That's his framing, not a description of anything that happened on the live network.

Veria's system identified two weaknesses that could be combined to bypass the ledger's monetary safeguards. The first was an integer overflow in the payment engine. Constructed trading offers could make the system miscalculate what a buyer owed, so sellers would get their full XRP payments while the buyer was charged only a fraction (effectively creating XRP that had never existed). The second sat in the supply-protection mechanism, which relied on the same flawed arithmetic and could fail to notice the new XRP.

Entry was cheap. The official vulnerability report said the attack needed only a few hundred XRP in largely refundable reserves plus ordinary fees, with hundreds of accounts and offers prepared in advance. The payment-engine code dates to 2015; the affected safeguard arrived in 2017.

Veria's AI built a working exploit and demonstrated it on a local network. RippleX engineers independently reproduced it and confirmed the newly generated XRP could be spent in later transactions.

RippleX said investigators found no evidence the flaw was exploited on public networks.

Why validators didn't wait for a vote

Changes to transaction-processing rules ordinarily need support from more than 80% of trusted validators for two consecutive weeks. Developers decided that would leave the bug exposed while the network voted on its own repair, and since XRPL software is open source, publishing the fix could've tipped off attackers before it took effect.

So RippleX, the XRP Ledger Foundation and validators coordinated an emergency upgrade that activated the protection immediately on servers running version 3.4.1. It shipped first as binaries, with source code temporarily withheld to limit reverse-engineering. The disclosure called it the first deliberate bypass of the amendment activation process for a transaction-processing change in more than a decade.

A heavily audited codebase

Liao said the XRPL codebase had been through more than a dozen audits and security contests since 2024, including one competition with a $550,000 prize pool. Its bug bounty programs have paid out more than $1 million. Veria said it received a $250,000 bounty, the program's maximum. Liao described it as the largest known reward for a vulnerability discovered entirely by an AI agent.

Frequently asked questions

How could the XRP Ledger flaw have created new XRP?

Veria Labs said two weaknesses could be combined. An integer overflow in the payment engine let constructed offers charge a buyer only a fraction while sellers received full XRP payments. The supply-protection mechanism used the same flawed arithmetic and could fail to recognize the newly created XRP.

Was any XRP actually minted or lost on the live network?

RippleX confirmed that no unauthorized XRP was created and no funds were lost, and investigators found no evidence of exploitation on public networks. The exploit was demonstrated on a local network and reproduced by RippleX engineers.

Why did the XRP Ledger skip its normal amendment vote for this fix?

Rule changes usually need support from more than 80% of trusted validators for two consecutive weeks. Developers determined that would leave the bug exposed during voting, and publishing open-source fix code could reveal the exploit. An emergency upgrade activated the protection immediately on version 3.4.1.