Avalanche Founder Warns AI Could Exploit XRP Ledger Bugs Before Crypto Falls
Avalanche founder warns AI could find XRP Ledger bugs before breaking cryptography, urging focus on code quality.
A bug in XRP Ledger's payment engine could have allowed creation of spendable XRP beyond the 100 billion cap. RippleX found no evidence of exploitation.
According to a security report released on Friday, a vulnerability in the XRP Ledger's payment engine could have enabled an attacker to generate spendable XRP from nothing. The bug was probably present since 2015 without detection.
The maximum supply of XRP is fixed at 100 billion tokens, currently valued at roughly $88.8 billion with a price of $1.41. Ripple's development division, RippleX, stated that no evidence of the flaw being exploited was discovered.
Within the XRP Ledger, there is an integrated marketplace that allows accounts to post offers for exchanging one token for another.
Per the report, an attacker would be able to create several hundred accounts. Each account would place an offer of a minuscule quantity of a token in return for a massive amount of XRP.
One payment could then purchase all offers simultaneously. The software's cumulative total would exceed the capacity of its counter, causing it to reset to a very small figure, similar to an odometer surpassing its maximum reading.
The selling accounts received full payment while the buyer spent nearly nothing. A validation check designed to detect newly created XRP relied on the same counter, thus also failing to notice the discrepancy.
The vulnerability was reported by researcher Cayden Liao and Veria AI via the XRPL bug bounty program on September 22.
Official XRPL vulnerability disclosure report published October 9, 2026.
â MartyParty (@martypartymusic) October 10, 2026
What happened
A researcher (Cayden Liao and Veria AI) reported an integer-overflow bug in the payment engine through the XRPL Bug Bounty program on September 22, 2026. It affected xrpld 3.4.0 and earlierâŠ
Typically, modifications to XRP Ledger rules require approval from over 80% of trusted validatorsâthe servers that verify transactionsâfor a period of two weeks.
The patch, included in server software version 3.4.1 released on September 25, became active the moment each operator updated their system.
âThis is the first time a change to transaction processing has deliberately shipped this way since the amendment system was introduced more than ten years ago,â RippleX said.
According to RippleX, a public vote would have revealed the flaw in open source code for several weeks during which it would remain exploitable. Over 80% of default validators updated their software on the release day, before the patch's code was made public.
The disclosure arrives one day after Cyber Capital founder Justin Bons, during an XRP decentralization debate with Ripple's David Schwartz, described the practice of selling XRP as decentralized as 'fraud.' The report states that the XRPL Foundation, RippleX, and validators jointly made the decision.
RippleX stated that voting will continue to be the standard process for future modifications.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
Avalanche founder warns AI could find XRP Ledger bugs before breaking cryptography, urging focus on code quality.
US spot Ethereum ETFs saw $56.1M leave on Oct. 9, a ninth straight daily outflow, while ETH short bets stood at $5B.
Mark KarpelĂšs discovered a hidden spy chip in a sealed Ledger wallet from Malaysia that could steal recovery phrases.
At XT8's X Space, XT Exchange COO Arman Achmed said the next billion users will come from easier, faster crypto experiences, not more blockchain education