It is reported that on September 21, 2026, XRP Ledger discovered a security vulnerability. Theoretically, attackers could create 18.45 trillion XRP tokens in a single transaction, which is more than 184 times the fixed supply of that token. Developers patched this decade-old flaw on September 25, 2026, and stated that no evidence of it being exploited on the public network was found.
Key Points
- The vulnerability originates from payment calculation code that was added in 2015.
- Veria AI has helped to discover a method for creating and spending XRP.
- An emergency patch was released without making the source code public.
- Engineer Mayukha Vadari warns that AI will make hidden security patches more susceptible to reverse engineering.
According to U.Today, this revelation prompted RippleX engineer Mayukha Vadari to warn that artificial intelligence is changing the way developers handle critical fixes. The team did not make the source code of the patches public when distributing the compiled software, and this practice has also been criticized for its consistency with the open-source commitments made on the internet.
CoinDesk reports that an engineer from RippleX reproduced this attack on a separate server and verified that the created XRP could indeed be used for subsequent transactions. This demonstration was different from what was observed on the public network, where developers did not find any signs of exploitation.
XRP Ledger How were security vulnerabilities discovered?

The security system Veria AI developed by Veria Labs detected this vulnerability on September 21, 2026. Researchers submitted a report the following day through the XRP Ledger vulnerability bounty program.
CoinDesk pointed out that the discoverers included researcher Cayden Liao as well as Veria AI. This vulnerability can be traced back to code introduced in 2015, which means it had existed for over a decade before it was discovered.
According to Veria Labs, a transaction that exploits this vulnerability can generate up to approximately 18.45 trillion XRP tokens, which is more than 184 times the fixed supply of 100 billion tokens for this cryptocurrency. All 100 billion tokens were created when the ledger went live in 2012; the software design is intended to prevent further issuance.
How payment calculations lead to the creation of XRP
This vulnerability is an integer overflow issue in the ledger payment engine, which occurs when it processes multiple transaction quotes through its built-in decentralized exchange. Under certain conditions, the total payment amount can exceed the range that the system's 64-bit calculations can handle.
Attackers can create hundreds of accounts, each using a very small amount of another token to exchange for abnormally high payments of XRP. Making a purchase for all these offers at once would result in a total payment of XRP that exceeds the calculated limit.
The software will not reject the transaction; instead, it will calculate a much smaller total amount. The selling account will receive all of their XRP, while the buying account will hardly have to pay any cost at all.
The security mechanism used to check for the creation of a new XRP relies on the same flawed total amount. Another mechanism that limits the amount a single account can receive was also unable to prevent this attack, as XRP was distributed across hundreds of accounts. According to CoinDesk, this setup only requires a few hundred XRP, most of which can be recovered, in addition to transaction fees.
The generated tokens can subsequently be spent or transferred to cryptocurrency exchanges. When submitting their report, researchers estimated that the market value of XRP was around $94 billion and believed that this vulnerability posed a threat to this entire value.
Urgent fix that does not require the disclosure of source code
On September 25, 2026, developers released xrpld 3.4.1 to fix this vulnerability. They distributed the binary file, but did not make the source code of this security patch public.
CoinDesk reports that the initial release notes did not specify what issues were fixed. The retention of the source code has also drawn criticism, with外界 questioning whether this practice is in line with the open-source nature of XRPL.
Vadari Warning regarding AI and security patches
Vadari warns that AI makes it more difficult for developers to quietly incorporate critical fixes into the normal public software release process. Her concern is that the patches will be quickly identified and reverse-engineered.
Vadari posted on X, saying: 'The situation has changed due to AI. You can no longer sneak in a critical vulnerability patch through the regular public release process, because you will be immediately discovered and subjected to reverse engineering.'
In this incident, the security system based on AI helped to identify a vulnerability that has existed since 2015, while RippleX confirmed in independent server tests that this vulnerability could be exploited.
This article was generated with the assistance of artificial intelligence and has been reviewed by an editorial team.












