Skip to content
SPY$778.57up +0.60%
Nasdaq$751.27up +0.49%
Nvidia$229.28down −0.52%
SpaceX$162.57up +1.25%
VIX14.84down −3.84%
BTC$82,972.00up +0.67%
Gold$4,183.41up +0.01%
Silver$60.37down −1.14%
Brent oil$104.54up +0.82%
DXY102.19down −0.17%
EUR/USD1.1203up +0.00%
USD/JPY158.31down −0.00%
2Y yield4.76%down −1 bp
5Y yield5.02%up +3 bp
10Y yield5.24%up +2 bp

Search FinPrism

Crypto · · 2 min read

XRP Ledger fixes 2015 bug that could have minted XRP past its 100bn cap

A hidden flaw in the XRP Ledger's built-in exchange could have let an attacker create new XRP for almost nothing. It was quietly patched, and developers say it was never used.

XRP Ledger fixes 2015 bug that could have minted XRP past its 100bn cap

The short answer

Developers of the XRP Ledger disclosed on October 9 that a flaw dating to 2015 could have let an attacker create spendable XRP out of thin air, breaking the token's fixed 100 billion supply. RippleX fixed it in a software update on September 25 and said it found no evidence the bug was exploited on any public network.

What’s going on here?

Researcher Cayden Liao and the firm Veria AI reported the flaw through the XRP Ledger's bug bounty program on September 22, CoinDesk reported. Engineers at RippleX, Ripple's developer arm, reproduced the attack the next day, rated it critical and merged a fix. The repair shipped in version 3.4.1 of the network's server software, xrpld, on September 25, and more than 80% of the default trusted validators were running it that same day, according to Bitcoin.com News. The public disclosure came on October 9. RippleX said there was no sign anyone had used the bug on a live network.

What does this mean?

XRP's design rests on a hard limit. All 100 billion tokens were created when the ledger launched in 2012, and the software is meant to make it impossible to add more. A fixed supply is a big part of why institutions are willing to hold and build on a cryptocurrency, because it means their holdings cannot be diluted by new tokens appearing.

The flaw sat in the ledger's native trading venue, where users list bids to trade tokens with each other. In theory, a bad actor might have opened hundreds of accounts, each offering a tiny amount of a token for a huge amount of XRP, and then sent one payment that filled every offer at once. The software added up those amounts using 64-bit arithmetic without checking for overflow. When a number grows too big for that space, it wraps around to a small one, much like an old car odometer rolling back to zero. Sellers would have been paid in full while the buyer was charged almost nothing, leaving brand-new XRP in the attacker's hands.

The ledger does run a safety check after each transaction to confirm no XRP was created, but it used the same faulty math, so it would have missed the problem. The cost of an attack was small: a few hundred XRP held as reserves, mostly recoverable, plus fees. That gap between cost and potential damage is why RippleX treated it as critical.

Developers shipped the fix without saying what it repaired and released the code only afterward, a common practice to avoid tipping off attackers. The episode adds to a series of long-hidden crypto security flaws found with the help of AI tools since July, CoinDesk noted.

The bull case

The process worked. The bug came in through a formal bounty program, was reproduced and fixed within three days, and most validators upgraded on day one, before anyone outside knew. No XRP was created and no funds were lost. For institutions weighing the network, a fast, quiet fix followed by full disclosure could strengthen confidence in how the XRP Ledger is maintained.

The bear case

A flaw that could break XRP's supply cap went unnoticed for about a decade, and the very check meant to catch it shared the same weakness. That raises questions about what else may be hidden in older code. It also lands as Ripple-backed Evernorth prepares to list on Nasdaq with about 473 million XRP on its books, putting supply integrity under a brighter spotlight.

Why should I care?

For markets:

XRP and companies holding it in their treasuries are most sensitive to doubts about the token's supply, though the lack of any exploit limits the immediate risk. Wider crypto markets may watch for further AI-assisted discoveries of old bugs.

The bigger picture:

Crypto assets depend on software working exactly as promised. Episodes like this show that even long-running networks can carry hidden risks, which is one reason crypto remains more volatile than traditional assets.

Market impact

Asset (ticker)Potential directionTimeframeConfidenceReason
XRP (XRP/USD) ↔ neutral Short term Low A serious flaw was found, but it was fixed before any exploit.

Potential impact, not investment advice.

Frequently asked questions

Was the XRP Ledger bug exploited?

No. RippleX, Ripple's developer arm, said it found no evidence the flaw was exploited on any public network. Normal transactions never came close to the conditions needed to trigger it. The bug was fixed on September 25 in xrpld 3.4.1, and disclosed publicly on October 9, 2026.

Can new XRP be created?

XRP is designed with a fixed supply of 100 billion tokens, all created at launch in 2012, and the software is built to stop any more being added. The recently disclosed bug could have broken that rule, but it has been patched and no new XRP was created.

Who found the XRP Ledger vulnerability?

Researcher Cayden Liao and Veria AI reported it through the XRP Ledger's bug bounty program on September 22, 2026. RippleX engineers reproduced the attack, rated it critical and released a fix three days later, before revealing the details publicly.

Sources: CoinDesk, Bitcoin.com News, CoinGape

Back to the latest