InvestAlso reported elsewhere2 publishers2 min readPublished
XRP Ledger's built-in exchange carried a decade-old bug that could mint XRP past its 100 billion cap
RippleX fixed a 2015-era XRP Ledger bug that let one payment create spendable XRP beyond the token's 100 billion supply cap. Both built-in safeguards would have missed it, so the cap's record on public networks rests on RippleX's finding of no exploitation.
The Investor · Invest desk

What happened
- The attack had one payment buy hundreds of tiny token offers priced in large XRP sums; the total was too big to count, so sellers were paid in full while the buyer paid almost nothing.
- Researcher Cayden Liao and Veria AI found the flaw and reported it internally on Sept. 22.
- RippleX engineers repeated the attack on a standalone server and showed that the XRP it minted was spendable in a subsequent transaction.
- On Sept. 25 developers released the fix as xrpld 3.4.1, the ledger's server software, without saying what it repaired.
Why it matters
- exposure Any xrpld server still on a version below 3.4.1 is now running code whose attack is described in a public security report.
- decision Operators who treat unexplained xrpld point releases as optional now have a case where one of them closed a path to creating XRP from nothing.
- precedent AI-assisted reviews have found long-hidden flaws in several crypto codebases since July, so a decade without an incident is weak evidence that a protocol's supply rules are sound.
The check that runs after every transaction to confirm no new XRP has appeared used the same miscounted total as the payment, so it would have passed the bad trade [11]. The second guard, a limit on how much XRP any one account can receive, would not have fired either, because the attack spread the proceeds across hundreds of accounts [12].
The 100 billion figure is a property of the software. Every XRP was created at the 2012 launch, and the code is built so no more can be added [7]. CoinDesk reported that institutions using the network rely on that cap, and that an attacker could have sold the newly made XRP on exchanges [8]. Anyone valuing XRP on a fixed float is relying on that code. The flaw sat in it for about a decade [2]. Setting up the attack, by the researchers' method, took a few hundred XRP to open accounts, most of it recoverable, plus transaction fees [13].
In our view the likeliest outcome is that RippleX's finding of no exploitation on any public network holds, and this stays a patched bug with no supply consequence [3]. The attack leaves a distinctive footprint, hundreds of accounts posting lopsided offers that one payment clears at once [9], and RippleX says its search found no evidence of it [3]. The other outcomes are less comfortable. A reconciliation of ledger history could find a payment matching that pattern, and the supply figure would need restating. Or the kind of AI-assisted review that found this flaw could find a second one in the same exchange code. An independent count of balances that turned up XRP no funded payment explains would prove our view wrong.
RippleX went from internal report to shipped fix in three days [16]. A holder who only owns XRP has nothing to install. The version question belongs to whoever runs xrpld, and the patched release is 3.4.1 [4].
CoinDesk places the find in a run of long-hidden crypto flaws that AI tools have helped uncover since July, among them the Coldcard wallet bug that led to the theft of at least 1,367 BTC and the vulnerabilities that left Core Lightning telling operators of bitcoin nodes to disconnect [14].
What to watch
- Whether an independent reconciliation of XRP Ledger history confirms RippleX's finding that the flaw was never exploited on a public network.
- Further findings from Cayden Liao, Veria AI or other AI-assisted reviews of the XRP Ledger's built-in exchange code.
- How quickly operators of xrpld servers move to 3.4.1 now that the attack has been described in public.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A flaw dating to 2015 could have allowed attackers to create and spend new XRP, violating the cryptocurrency's fixed supply of 100 billion tokens.
- [2]
CoinDesk's headline called the flaw a decade-old bug that could create billions of dollars in XRP from nothing.
- [3]
RippleX said it found no evidence the flaw was exploited on any public network.
- [4]
Developers shipped the fix in xrpld 3.4.1, the ledger's server software, on Sept. 25 without disclosing what it repaired.
- [5]
The bug was found by researcher Cayden Liao and Veria AI and internally reported on Sept. 22.
- [6]
Engineers at RippleX, Ripple's developer arm, reproduced the attack on a standalone server and confirmed the newly created XRP could be spent in a later transaction.
- [7]
All 100 billion XRP were created when the ledger launched in 2012, and its software is built so no more can ever be added.
- [8]
The vulnerability could have allowed an attacker to create XRP from nothing and sell it on exchanges, undercutting a supply cap that institutions using the network rely on.
- [9]
An attacker would open hundreds of accounts, have each one offer a tiny amount of a token in exchange for an unusually large amount of XRP on the ledger's built-in exchange, then send a single payment that bought every offer at once.
- [10]
The total XRP owed would be too large for the software to count correctly, so the attacker's selling accounts would be paid in full while the buying account was charged almost nothing.
- [11]
The XRP Ledger runs a check after every transaction to make sure no new XRP has appeared, but that check relied on the same miscounted total and would have missed the attack.
- [12]
A separate limit on how much XRP a single account can receive would not have triggered, because the attack spread the XRP across hundreds of accounts.
- [13]
The researchers' method needed only a few hundred XRP to open the accounts, most of which could be recovered, plus transaction fees.
- [14]
The incident joins a run of long-hidden crypto security flaws surfaced with AI help since July, including the Coldcard wallet bug behind the theft of at least 1,367 BTC and the vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect.
- [15]
The flaw was described in a security report published Friday, according to CoinDesk.
- [16]
RippleX shipped the fix three days after the flaw was internally reported.
Derived
Sources
2 independent publishers whose own reporting we read for this story.
- coindesk.comXRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing
1 article · October 9, 2026
- cryptobriefing.comRipple fixes 2015 bug preventing unauthorized XRP minting
1 article · October 9, 2026