An AI Agent Found a Bug That Could Have Minted 18 Trillion XRP. Here's Why It Matters Less Than You Think.
A single transaction could have created 180 times XRP's total supply. The fix required bypassing the network's own governance rules. But the real story isn't the bug. It's what the response reveals about trust, and about who's using AI to find the next one.
I was on a call with a former bank examiner when the news crossed my screen. She'd spent twenty years inspecting financial plumbing, the kind that moves billions without anyone outside a windowless room knowing. When I told her an AI agent had just found a decade-old bug in the XRP Ledger that could have minted 18 trillion tokens, she laughed. Not because it was funny. Because, as she put it, that's the sound of everyone realizing the vault door was never locked. They just forgot to check.
That's the fault line this story exposes. Not the bug itself, which is fixed, and not the market impact, which was minimal, given that nothing actually happened. It's the structural problem of legacy financial code running on trust and hope. And it's the accelerating arms race between AI security tools and the human engineers trying to stay ahead of them.
The Mechanics: How 18 Trillion XRP Almost Appeared Out of Thin Air
Here's what Veria Labs found when its AI system went poking throughrippled, the software that runs the XRP Ledger. The bug wasn't one flaw. It was two. The first lived in the payment engine, in code that dates back to 2015. A carefully constructed trading offer could cause an integer overflow, the kind of arithmetic error that makes a computer miscalculate how much a buyer owes. The seller would get paid in full. The buyer would be charged a fraction of the real amount. And the difference? That XRP would simply exist where it hadn't before.
The second flaw was in the supply safeguard, the mechanism that's supposed to catch exactly this kind of creation. It was introduced in 2017. And it relied on the same broken arithmetic, so it wouldn't have noticed the new tokens at all. Two wrongs made a very dangerous right.
The scale is hard to wrap your head around. An attacker could have generated roughly 18 trillion XRP in a single transaction. XRP's original supply was 100 billion. That's 180 times the total. According to Veria founder Cayden Liao, the flaw threatened the cryptocurrency's $94 billion market capitalization by undermining the one thing every fixed-supply asset promises: that the supply is, in fact, fixed.
What did the attack require? A few hundred XRP in reserves, most of which would have been refundable, plus normal transaction fees. Hundreds of accounts, prepared in advance. That's it. No nation-state resources. No insider access. Just patience and a little technical knowledge, the kind that's been commoditized over the past two years.
Veria's AI didn't just find the bug. It assembled a working exploit on a local network. RippleX engineers reproduced it independently and confirmed the newly created XRP could be spent in subsequent transactions. The discovery was reported on Sept. 22. The patch went live three days later. The public disclosure came on Oct. 9. And on that last date, RippleX confirmed what everyone needed to hear: no unauthorized XRP was created, no funds were lost, and there's no evidence of exploitation on public networks.
The Governance Bypass: When the Rules Themselves Become the Risk
Here's where this gets uncomfortable. XRPL has a governance process for a reason. Protocol changes that affect transaction processing require more than 80% support from trusted validators for two consecutive weeks. It's slow by design. It's meant to prevent exactly the kind of unilateral action that centralized systems take for granted.
Developers bypassed it anyway. They had to.
Following the amendment process would have left the vulnerability exposed for weeks while the network voted on a fix. And because XRPL is open source, publishing the patch could have handed attackers a roadmap before the protection was active. So RippleX, the XRP Ledger Foundation, and validators coordinated an emergency upgrade that activated immediately on servers running version 3.4.1. The patch went out as binaries first, with source code temporarily withheld, to limit reverse-engineering risk during deployment.
This was the first deliberate bypass of the amendment process for a transaction-processing change in more than a decade. Reading the legislative tea leaves, it won't be the last.
The calculus was brutal but clear. Servers running different versions could disagree on whether an exploit transaction was valid. That could disrupt consensus or halt the network entirely. Developers concluded a temporary interruption was preferable to letting counterfeit XRP enter circulation. More than 80% of validators on the default trusted list had upgraded by Sept. 25, which substantially reduced the risk. But the risk was real.
Vet, an XRPL Foundation contributor, said the coordinated response preserved network integrity and established version 3.4.1 as the new minimum software requirement. That's the diplomatic version. The blunter version is that the network's governance model, which exists to prevent this kind of thing, had to be set aside to prevent something worse. That's not a failure. It's a trade-off. But it's one that every decentralized network should be thinking about right now.
The Real Story: AI Is Rewriting the Security Playbook, and Not Everyone Wins
Let's pull back. The XRPL codebase has undergone more than a dozen audits and security contests since 2024, including one competition with a $550,000 prize pool. Bug bounty programs have paid out more than $1 million. And none of it caught this. An AI system did, in a matter of days, and the bounty for that discovery was $250,000, the program's maximum. Liao described it as the largest known reward for a vulnerability discovered entirely by an AI agent.
That number matters. It's a signal. AI-assisted vulnerability discovery is now competitive with, and in this case superior to, years of human-led review. And it's only getting better.
RippleX is already adapting. J. Ayo Akinyele, the organization's head of engineering, acknowledged that the vulnerability demonstrated the need to revisit longstanding assumptions about the network's design. He outlined plans to expand AI-assisted vulnerability discovery, strengthen adversarial testing, and increase scrutiny of legacy components, including the payment engine, consensus mechanisms, and peer-to-peer networking. The organization also plans to accelerate formal verification, a mathematical technique that proves whether software meets specific security properties, building on existing work with the Lending Protocol and Single Asset Vault.
Akinyele said AI is fundamentally accelerating vulnerability discovery, putting pressure on developers to find weaknesses before malicious actors deploy similar tools. Vet echoed that concern, warning that increasingly capable AI systems could make previously obscure vulnerabilities easier to exploit.
So here's the question I keep coming back to. If AI can find a decade-old bug in three days, what's hiding in the rest of the infrastructure? Bitcoin's codebase. Ethereum's clients. The bridges and custodians and exchanges that hold billions in user funds. According to two people familiar with the negotiations around crypto security standards, the industry has been treating AI as a tool for building. It's just as effective at tearing down.
My honest take: this is a wake-up call, but not the one most people will hear. The bug was fixed. The market didn't crash. XRP's price barely moved. The system worked, even if it had to bend its own rules to do it. The real lesson isn't that XRP was vulnerable. It's that every legacy financial system is vulnerable to this exact kind of attack, and most of them don't have an AI agent scanning the code. They also don't have a governance process that can be bypassed in an emergency. That's a problem.
The October 9 disclosure introduced one specific procedural change: security findings previously classified as resolved must now be retested against release candidates before being closed. That's incremental, but it's the right direction. The broader shift is cultural. Developers are going to have to assume their code is already compromised, that the bug is already there, and that someone smarter and faster is looking for it. That's not paranoia. It's the new baseline.
The question now is whether the rest of the industry catches up before the next AI agent finds something it can't fix in three days. And who audits the auditors? Or in this case, who watches the AI that watches the code?
Because the arms race is on. And if you think your protocol is safe because it's been audited a dozen times, you're already behind.
Explore More
Key Terms Explained
An autonomous program that can perceive on-chain data, make decisions using machine learning models, and execute blockchain transactions without human intervention.
The first cryptocurrency, created in 2009 by the pseudonymous Satoshi Nakamoto.
A reward offered by crypto projects for completing specific tasks like finding bugs, writing code, or creating content.
A reward program where protocols pay security researchers for finding and responsibly disclosing vulnerabilities.