XRP Ledger developers have disclosed a critical payment-engine bug that could have created spendable XRP from nothing. The flaw had existed in the code since roughly 2015, but the XRPL team says it found no evidence that anyone exploited it on a public network.
The official XRPL vulnerability report says the problem was an integer overflow in the payment engine. A specially constructed payment could consume hundreds of unusual order-book offers whose XRP totals exceeded the size of a 64-bit integer. Instead of failing, the total could wrap around to a very small number.
That is the same basic programming failure behind many classic overflow bugs: a number grows beyond the range its data type can represent and wraps into another value. BitcoinVersus recently covered the underlying concept in C integer types and memory representation.

How the Bug Could Create XRP
The exploit required a deliberately abnormal setup. An attacker could create hundreds of accounts, place offers asking for extremely large amounts of XRP, then send one specially constructed payment through those offers.
Each offer owner could receive the full amount individually while the buyer was charged only the wrapped-around total. The ledger’s separate safety check against creating new XRP used similar arithmetic, so it could wrap in the same way and fail to detect the imbalance.
The Block reported that Veria Labs co-founder Cayden Liao estimated one proof-of-concept transaction could have created about 18 trillion XRP. That exact figure comes from Veria’s analysis; the official XRPL disclosure more conservatively says the flaw could have created spendable XRP “far beyond” the intended total supply.
RippleX engineering leadership said the incident is pushing the team toward more AI-assisted bug hunting, fuzzing, and formal verification.
The Fix Was Treated as an Emergency
The bug was reported on September 22. RippleX reproduced the exploit, confirmed the newly created XRP could be spent, and raised the issue to critical severity. The fix shipped three days later in xrpld 3.4.1.
Normally, transaction-rule changes on XRPL go through an amendment vote and remain pending until more than 80% of trusted validators support them for two weeks. Developers intentionally skipped that process for this fix because publishing an open-source patch while the vulnerability remained active would have exposed the exploit path for weeks.
The XRP Ledger Foundation explains the normal amendment process that this emergency security fix bypassed.
The decision carried its own risk: upgraded and unupgraded servers temporarily followed different rules for the malicious transaction pattern. Developers concluded that even a temporary network halt would have been preferable to validating an exploit that manufactured new XRP.
An AI Agent Helped Find It
XRPL credits Cayden Liao and Veria AI with discovering the overflow. The Block reports that Ripple paid the program’s maximum $250,000 bounty and that Veria says the vulnerability was discovered entirely by an AI agent.
RippleX engineer Mayukha Vadari discussed how AI changes the disclosure problem for critical open-source vulnerabilities.
The discovery fits a broader shift in security research. BitcoinVersus recently covered how AI-generated bug reports are changing open-source bounty programs. The value comes when automated discovery is paired with reproducible evidence and careful human verification.
What Server Operators Need to Know
XRPL says all server operators should run version 3.4.1 or newer. The release also fixed a separate Batch transaction validation issue, and older servers are now amendment-blocked because the related fix has activated on Mainnet.
The episode is also a reminder that software security is not finished when code ships. Patches, validation, and upgrades remain part of operating any networked system, a principle BitcoinVersus explains in why computers need security updates.
What Is Known
- The payment-engine overflow existed for roughly a decade.
- The XRPL team reproduced a working exploit that created spendable XRP.
- The flaw required a deliberately constructed transaction and could not occur through normal trading by accident.
xrpld 3.4.1patched the overflow.- More than 80% of default-list validators were upgraded on the release day.
- XRPL says it found no evidence the bug was exploited on a public network.
The vulnerability was severe because it challenged one of a cryptocurrency ledger’s most basic rules: software should not be able to manufacture native currency outside the protocol’s intended issuance rules. The important part for users today is that the flaw was reported, reproduced, patched, and publicly disclosed only after most trusted validators had upgraded.
BitcoinVersus.Tech
Editor’s Note: The roughly 18 trillion XRP proof-of-concept estimate is attributed to Veria Labs and reported by The Block. XRPL’s primary disclosure confirms that the vulnerability could create spendable XRP far beyond the intended supply but does not use that exact figure. Developers report no evidence of exploitation on a public network.
We volunteer daily to improve the credibility of the information on this platform. If you would like to support the research, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb
BitcoinVersus.tech is not a financial advisor. This media platform reports on technical and financial subjects purely for informational purposes.

Leave a Reply