XRP Ledger Patched a Decade-Old Bug That Could Mint XRP Out of Thin Air
Published October 10, 2026, 11:50 PKT. Based on CoinDesk's October 9 report, RippleX's security disclosure and TokenPost's technical write-up.
A security flaw that had been sitting in the XRP Ledger's payment engine since 2015 could have let an attacker create XRP out of thin air, according to a report published October 9 by CoinDesk. RippleX, Ripple's developer arm, confirmed the bug, reproduced the attack on a standalone server and quietly shipped the fix in the xrpld 3.4.1 server software on September 25. It said it found no evidence the flaw was ever exploited on a public network.
The 2015 flaw that broke the supply cap
All 100 billion XRP were created when the ledger launched in 2012, and the software is designed so no more can ever be added. The vulnerability broke that guarantee. It affected xrpld 3.4.0 and every earlier version of the ledger's server software, and researchers believe the flaw dates to when the payment engine was written in 2015, TokenPost reported.
The bug was found by security researcher Cayden Liao and Veria AI, and internally disclosed to Ripple developers on September 22 through the ledger's bug bounty program, CoinDesk reported. Three days later, the patch went out in xrpld 3.4.1 without disclosing what it repaired, and more than 80% of validators on the ledger's default trusted validator list were already running the fixed version by September 25.
How one payment printed XRP from nothing
The attack worked through the ledger's built-in exchange, where accounts post offers to swap one token for another. An attacker would open hundreds of accounts, have each one offer a tiny amount of a token in exchange for an unusually large amount of XRP, then send a single payment that bought every offer at once, according to the report.
The total XRP owed would be too large for the software to count correctly, so the attacker's selling accounts would be paid in full while the buying account was charged almost nothing, leaving the attacker with XRP that had not existed before. The setup cost only a few hundred XRP in account and offer reserves, plus transaction fees, and most of the reserves could be recovered afterwards, TokenPost reported.
Why the ledger's own checks missed it
The XRP Ledger runs a check after every transaction to make sure no new XRP has appeared, but that check relied on the same miscounted total and would have missed it, CoinDesk reported. A separate limit on how much XRP a single account can receive would not have triggered either, because the attack spread the new XRP across hundreds of accounts.
RippleX engineers reproduced the exploit on a standalone server and confirmed that the newly created XRP could be spent in a later transaction, according to the report. The researchers who disclosed the flaw demonstrated the attack the same way before submitting it through the bounty program.
A decade-old secret patched in silence
The quiet September 25 fix kept the vulnerability's details secret while validators upgraded, a standard practice for preventing copycat attacks before the patch is widely installed. The public only learned what had been repaired when CoinDesk published the security report on October 9, more than two weeks after the update shipped.
Long-hidden flaws surfacing in mature blockchain codebases are not new, and neither are AI-assisted discoveries. The report noted that the XRP Ledger flaw joins a run of long-buried crypto security bugs surfaced with AI help since July, including a Coldcard wallet bug tied to the theft of at least 1,367 BTC and vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect.
This article is news reporting and is not investment advice.
Sources
- CoinDesk, XRP Ledger Patched Decade-Old Bug That Could Create Billions of Dollars in XRP From Nothing (Oct. 9, 2026), primary source for the vulnerability details, the disclosure timeline and RippleX's confirmation
- RippleX, internal security report and xrpld 3.4.1 release, primary source for the reproduction of the exploit, the absence of public-network exploitation and the September 25 patch date
- TokenPost, XRP Ledger Patches Flaw That Could Have Created XRP Beyond 100 Billion Supply (Oct. 10, 2026), secondary source for the affected versions, validator upgrade figures and the attack-cost breakdown
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
Ledger Drain Grows to $92.9M as Tether Freezes $10M and Thief Sends 1,254 ETH to Tornado Cash
Bitquery's forensic investigation traced the suspected Ledger/CryptoBilis wallet drain to $92.9 million taken from 311 wallets across five blockchains, up from the $86 million first reported. Tether froze $10 million in USDT tied to the theft, while the thief sent 1,254 ether into Tornado Cash on October 9.
New York Permanently Bars Celsius Founder Mashinsky in $35M Fraud Settlement
New York Attorney General Letitia James secured a permanent ban keeping former Celsius CEO Alex Mashinsky out of the securities, commodities and cryptocurrency industries, plus up to $35 million in conditional payments, settling the state's 2023 civil lawsuit over claims he misled hundreds of thousands of investors about the safety of their Celsius deposits.
Kishu Inu Founder Indicted on Wire Fraud Charges Over $9 Million Token Scheme
A federal grand jury in Chicago indicted Kishu Inu founder Alexander Sisemore on October 6, 2026, on three wire fraud counts, alleging he secretly kept about 6% of the meme coin's supply and profited over $9 million while telling investors the launch was fair.


