Critical Flaw Dating From 2015 Quietly Patched by RippleX
The XRP Ledger has been patched against a critical overflow bug that had lurked in its payment engine since 2015, a flaw researchers say could have allowed an attacker to conjure roughly 18 trillion XRP out of thin air in a single transaction. That figure, estimated by Veria Labs co-founder Cayden Liao, is about 184 times the token’s original total supply of 100 billion, the hard cap that has underpinned XRP’s fixed-supply narrative since the ledger launched.
The vulnerability was reported on September 22, 2026 by Veria Labs, whose AI agent discovered the flaw and produced a working exploit. RippleX, the engineering arm closely associated with the ledger’s development, shipped a fix in xrpld version 3.4.1 just three days later, on September 25. Notably, the developers did not wait for the validator amendment vote that typically governs protocol-level changes on the XRPL, a decision that underscores the severity they attached to the finding. Veria received the maximum bug bounty of $250,000 for the disclosure.
Developers stated there was “no evidence that this issue was exploited on any public network.” That single sentence is doing a great deal of work. It means the incident should be understood as a successful preventative fix rather than a confirmed inflation event, and the ledger’s balances and supply figures remain intact. But the near miss is a sobering illustration of how long-lived financial software can carry dormant arithmetic errors with catastrophic potential.
How the Overflow Attack Worked
The flaw sat in the payment engine’s handling of transactions that execute many order-book trades at once. When the engine added up the trade amounts, it performed no overflow check. In computing terms, an overflow occurs when a sum grows beyond the maximum value a fixed-width number can hold, causing the total to “wrap around” to a much smaller figure. In the XRPL’s case, a sufficiently large total could therefore wrap to a trivially small number, allowing a malicious payment to bypass the accounting rules that are meant to ensure every transaction balances.
The attack scenario described in the disclosure is strikingly simple in outline. An attacker could have created several hundred accounts, each listing tiny fractions of XRP, or other assets, for sale in exchange for an enormous XRP amount. The attacker would then settle all of those offers in a single transaction. Because the payment engine’s summation of the trade amounts could be made to overflow, the ledger would fail to register the true magnitude of the XRP being delivered, and the attacker would walk away with spendable tokens that never existed.
Liao’s estimate puts the yield of one exploit transaction at approximately 18 trillion XRP. To grasp the scale, the entire original supply was capped at 100 billion tokens, and that figure only ever shrinks over time because transaction fees are burned. An exploit of this size would not merely have bent the supply curve; it would have obliterated the fixed-cap proposition entirely, distorting balances across the ledger and calling into question the integrity of every account holding the asset.
The fact that the bug dated from 2015 is central to why it matters beyond the XRPL itself. This was not a regression introduced in a recent release, nor a mistake in newly shipped code that had yet to be battle-tested. It was a decade-old arithmetic error that survived years of network upgrades, audits, bug bounty programmes and intense public scrutiny of one of the most closely watched ledgers in the industry. It was found not by a conventional audit but by an AI agent, which Liao’s firm says both identified the vulnerability and produced a working exploit. That detail will not be lost on security teams elsewhere, and it may accelerate the adoption of automated vulnerability discovery across blockchain codebases.
Market and Regulatory Implications
For XRP holders, the immediate practical news is reassuring: the fix is live, no exploitation occurred, and the supply cap remains unbroken. In the short term, a cleanly handled disclosure of this kind can even burnish a network’s reputation, because it demonstrates that the responsible disclosure pipeline works, that the development team can move quickly, and that the bounty programme is funded at a level commensurate with the stakes. A $250,000 maximum payout for a bug that could have minted 18 trillion tokens is, by any measure, an extraordinary return on investment for the ledger’s security budget.
The longer-term implications are more nuanced. The XRPL’s fixed supply of 100 billion tokens has long been one of its core marketing points, a contrast with networks where issuance is discretionary or governed by inflation schedules. Any credible threat to that cap, even one neutralised before exploitation, invites harder questions from institutional participants. Custodians, market makers and regulated exchanges that list XRP all rely on the assumption that the ledger’s accounting is sound. A near miss of this magnitude will prompt some of them to review their own assumptions about how quickly a ledger-level flaw could propagate into their balances and reporting.
There is also a governance angle worth watching. The XRPL ordinarily relies on validator amendment votes, a decentralised process in which network operators signal approval before protocol changes activate. By shipping the fix without waiting for that vote, RippleX prioritised urgency over process. Defenders will argue that a bug of this severity demanded immediate action and that the amendment mechanism is too slow for critical security patches. Critics may note that the episode illustrates how much practical authority still rests with a single engineering team, a tension that every proof-of-stake and federated network grapples with when security and decentralisation collide. Expect the incident to feed into ongoing debates about emergency patch procedures across the industry.
For regulators, the episode is a useful data point in a live debate about systemic risk in digital asset markets. A hypothetical 18 trillion XRP appearing on a major public ledger is precisely the kind of event that could move prices across the entire market, given XRP’s deep liquidity and listing footprint. Supervisors who have been pressing exchanges and custodians on operational resilience will read the disclosure as evidence that even mature, decade-old networks can harbour existential flaws. It strengthens the case for mandatory disclosure timelines, coordinated patching standards and bounty programmes sized to the actual damage a bug could cause, rather than to the effort of finding it.
What This Says About Long-Lived Blockchain Code
The uncomfortable lesson is that age is not the same as assurance. Ten years of uninterrupted operation, during which the XRP Ledger settled trillions of dollars in value, did not flush out a flaw that a sufficiently motivated attacker could have used to break the network’s most fundamental invariant. Code review catches many things, and formal verification catches more, but arithmetic edge cases at extreme magnitudes are notoriously easy to overlook precisely because they never occur in ordinary traffic. No legitimate user ever tries to settle hundreds of offers for astronomical amounts in one transaction, so the code path sat untouched by real-world activity.
The discovery also raises the bar for every other ledger. If an overflow bug of this consequence survived a decade on the XRPL, similar classes of flaw, unchecked arithmetic, integer edge cases, assumptions baked in during a network’s earliest days, almost certainly persist elsewhere in the industry. Older chains that have never undergone a modern security review of their original consensus and transaction code should treat this as a prompt. The Veria Labs result suggests AI-assisted discovery can reach corners that human auditors have historically missed, and bounty programmes should be recalibrated accordingly.
For the XRPL community, the immediate task is confidence-building. The developers’ statement that there is no evidence of exploitation on any public network is the key fact, and it should be repeated prominently. Beyond that, the network’s response speed, three days from report to patch, sets a standard that other projects will now be measured against.
The Analyst’s View
In the end, this story is about a bullet dodged rather than a wound suffered. The XRP Ledger caught a decade-old flaw capable of minting 184 times its original supply, patched it within days, paid out a quarter of a million dollars for the privilege, and carried on without a single token misaccounted. That is the system working. But the narrowness of the escape deserves emphasis: the difference between a footnote in a security bulletin and a market-shaking inflation event came down to whether the right researcher, or the right AI agent, found the bug before the wrong person did. Fixed-supply narratives are only as strong as the arithmetic underneath them, and arithmetic, as this episode shows, can hide its mistakes for a very long time.