Critical XRP Ledger Flaw Had Potential to Generate Trillions of XRP

A previously unknown flaw in the XRP Ledger remained undetected for about ten years, according to disclosures from its developers. The issue involved payment calculations tied to the network’s decentralized exchange and could have let a single transaction create 18.45 trillion XRP, far beyond the intended 100 billion supply. An AI security tool found the bug on September 21, and the team released an emergency patch while temporarily withholding source code.
The ledger’s developers traced the defect to 2015 code governing payment calculations on its built-in exchange, especially when many offers were handled together. Under certain arrangements, an integer overflow could produce a much smaller charge than intended, letting a seller collect full payment while a buyer paid only a fraction. A related weakness existed in the safeguard meant to stop unearned XRP creation.
Veria Labs’ AI tool flagged the issue on September 21; it was reported through the official bounty program the next day. Developers issued emergency update xrpld 3.4.1 on September 25 and initially withheld source code. They found no sign of exploitation on the public network. XRP’s market value at notification was about $94 billion.
If such a flaw had been exploited, XRP holders, traders, exchanges, and payment services could have faced sudden supply inflation, price disruption, and loss of confidence. The emergency patch and temporary source-code withholding may also intensify debate over open-source transparency versus security. More broadly, AI-assisted discovery could push crypto projects to patch critical bugs faster and communicate more carefully, potentially affecting how developers, investors, and regulators view ledger safety.