MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / DeFi / XRP Ledger Patched a Decade-Old Bug That Could Mint XRP Out of Thin Air
DeFi

XRP Ledger Patched a Decade-Old Bug That Could Mint XRP Out of Thin Air

By MABOnChain Desk · Published · Updated · 5 min read

Editorial digital-art illustration of the XRP Ledger blockchain as a dark futuristic payment engine with golden XRP coins streaming from a cracked mathematical equation matrix, a magnifying glass exposing an overflow bug in the counting code, electric blue accents on deep navy

Published October 10, 2026, 11:50 PKT. Based on CoinDesk's October 9 report, RippleX's security disclosure and TokenPost's technical write-up.

A security flaw that had been sitting in the XRP Ledger's payment engine since 2015 could have let an attacker create XRP out of thin air, according to a report published October 9 by CoinDesk. RippleX, Ripple's developer arm, confirmed the bug, reproduced the attack on a standalone server and quietly shipped the fix in the xrpld 3.4.1 server software on September 25. It said it found no evidence the flaw was ever exploited on a public network.

The 2015 flaw that broke the supply cap

All 100 billion XRP were created when the ledger launched in 2012, and the software is designed so no more can ever be added. The vulnerability broke that guarantee. It affected xrpld 3.4.0 and every earlier version of the ledger's server software, and researchers believe the flaw dates to when the payment engine was written in 2015, TokenPost reported.

The bug was found by security researcher Cayden Liao and Veria AI, and internally disclosed to Ripple developers on September 22 through the ledger's bug bounty program, CoinDesk reported. Three days later, the patch went out in xrpld 3.4.1 without disclosing what it repaired, and more than 80% of validators on the ledger's default trusted validator list were already running the fixed version by September 25.

How one payment printed XRP from nothing

The attack worked through the ledger's built-in exchange, where accounts post offers to swap one token for another. An attacker would open hundreds of accounts, have each one offer a tiny amount of a token in exchange for an unusually large amount of XRP, then send a single payment that bought every offer at once, according to the report.

The total XRP owed would be too large for the software to count correctly, so the attacker's selling accounts would be paid in full while the buying account was charged almost nothing, leaving the attacker with XRP that had not existed before. The setup cost only a few hundred XRP in account and offer reserves, plus transaction fees, and most of the reserves could be recovered afterwards, TokenPost reported.

Why the ledger's own checks missed it

The XRP Ledger runs a check after every transaction to make sure no new XRP has appeared, but that check relied on the same miscounted total and would have missed it, CoinDesk reported. A separate limit on how much XRP a single account can receive would not have triggered either, because the attack spread the new XRP across hundreds of accounts.

RippleX engineers reproduced the exploit on a standalone server and confirmed that the newly created XRP could be spent in a later transaction, according to the report. The researchers who disclosed the flaw demonstrated the attack the same way before submitting it through the bounty program.

A decade-old secret patched in silence

The quiet September 25 fix kept the vulnerability's details secret while validators upgraded, a standard practice for preventing copycat attacks before the patch is widely installed. The public only learned what had been repaired when CoinDesk published the security report on October 9, more than two weeks after the update shipped.

Long-hidden flaws surfacing in mature blockchain codebases are not new, and neither are AI-assisted discoveries. The report noted that the XRP Ledger flaw joins a run of long-buried crypto security bugs surfaced with AI help since July, including a Coldcard wallet bug tied to the theft of at least 1,367 BTC and vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading

Regulation

New York Permanently Bars Celsius Founder Mashinsky in $35M Fraud Settlement

October 10, 2026 · 4 min read

New York Attorney General Letitia James secured a permanent ban keeping former Celsius CEO Alex Mashinsky out of the securities, commodities and cryptocurrency industries, plus up to $35 million in conditional payments, settling the state's 2023 civil lawsuit over claims he misled hundreds of thousands of investors about the safety of their Celsius deposits.