One of the world’s largest crypto networks has patched a bug that could have let an attacker print counterfeit crypto out of thin air and spend it like the real thing. According to a vulnerability disclosure report published on XRPL.org on Friday, an integer overflow in the XRP Ledger’s payment engine could have let one cheap, rigged transaction mint coins beyond the network’s fixed supply. It’s the latest of several money-printing bugs in crypto this year, including a Zcash flaw in June and a Liquid Network exploit last month that let attackers cash out unbacked coins for real bitcoin.
In terms of the technical details, here’s how the exploit would have worked. When one payment consumed many offers from the XRP Ledger’s built-in order book, the engine summed the XRP owed using 64-bit math with no overflow check. If the total got too large, it would wrap around to a tiny number, paying offer owners in full while charging the buyer almost nothing.
The disclosure report says the bug likely dates all the way back to 2015, when the current payment engine was written.
To turn a profit with this bug, an attacker would need just a few hundred accounts posting absurdly priced offers, one payment sweeping through them, and a few hundred dollars’ worth of XRP in refundable reserves plus fees. “An attacker could have created spendable XRP far beyond the total supply in a single validated transaction,” the disclosure report says. At the time of this writing, CoinGecko puts the value of XRP’s entire circulating supply at just under $88 billion. That said, it’s unclear how much real value a hypothetical attacker would have been able to extract while selling large sums of XRP into the market.
Researcher Cayden Liao reported the bug via the XRPL bug bounty program on September 22nd, and RippleX, Ripple’s developer arm, reproduced it on a private test server before rating it critical. An emergency release of the xrpld software followed on September 25th. The release also fixed a second, less severe bug in XRPL’s not-yet-activated Batch feature that could have halted the network if left in place.
“Due to the security-sensitive nature of the fix, the source code for this release has not been published yet,” the release notes said, and the changelog described the patch only as assorted integer-arithmetic hardening in the payment engine and ledger helpers. The code hit GitHub on Friday.
“The fix shipped in xrpld 3.4.1. We have found no evidence that this issue was exploited on any public network,” the disclosure report claims, spinning the episode as a win. “Findings like this class of long-dormant issue are what the [bug bounty] program exists to produce.”
No Vote Required
Normally, XRP Ledger rule changes need a validator vote. “If an amendment receives more than 80% support for two weeks, the amendment passes and the change applies permanently to all subsequent ledger versions,” the XRPL documentation explains, adding that such bug fixes also require amendments.
This latest fix for the inflation bug skipped the vote, taking effect on each server once it upgraded. “This is the first time a change to transaction processing has deliberately shipped this way since the amendment system was introduced more than ten years ago,” the disclosure report says, arguing a vote would have left a visible bug exploitable for weeks. The disclosure report concedes that the shortcut risked splitting the network while servers upgraded. “In this case, a network halt would actually be preferable to processing exploit transactions and creating an incorrect ledger state that would be hard to roll back,” it says.
By default, XRPL servers trust two validator lists, one published by the XRPL Foundation and one by Ripple. Both currently name the same 35 validators, one of which identifies itself with a ripple.com domain in Ripple’s list. “Publishers aren’t involved in day-to-day validation of new transactions, but they do wield significant power in selecting which validators are widely trusted,” the XRPL documentation acknowledges.
More than 80% of those 35 validators were running the closed-source binary on release day, according to the disclosure report. “I am one of 35 dUNL nodes, and I had the chance to refuse the upgrade,” validator operator and HashLabs Chief Technology Officer Daniel Keller wrote on X. “I downloaded the bin, diffed it, and based on how serious the fix was, updated my node.”
The OG of Centralized Crypto
A few dozen hand-picked operators adopting an unannounced rule change within a day is exactly the kind of centralization XRP critics have long complained about. For example, as far back as 2013, early Bitcoin developer Greg Maxwell argued that Ripple’s validator design would likely leave users trusting only a few big nodes, effectively making it a centralized system, and that XRP was basically just another pre-mined altcoin.
Much of crypto is now centralizing around corporate blockchains and centrally issued stablecoins, but Ripple is the OG of centralized crypto profiteering. According to XRPL.org, all 100 billion XRP were created before the company that became Ripple was formed, and the founders then gifted it 80 billion. “Since then, the company has regularly sold XRP, used it to strengthen XRP markets and improve network liquidity, and incentivized development of the greater ecosystem,” the site says.
Attorney Preston Byrne has argued that the founders agreed to allocate 80% of the coins to the company the day it was incorporated in September 2012, months before the ledger’s first transactions on January 1st, 2013. “In my opinion the answer is ‘yes, Ripple created XRP, they own most of it and it was issued after company formation,’” he wrote.
In December 2020, the SEC sued Ripple and two executives for allegedly raising more than $1.3 billion through an unregistered securities offering. After Trump’s 2024 election win, Ripple gave roughly $4.9 million in XRP to his inaugural committee. Before the election, co-founder Chris Larsen had given more than $11.8 million to pro-Harris PACs, although Ripple’s chief legal officer, Stuart Alderoty, personally gave $300,000 in XRP to a Trump fundraising committee. In August 2025, the SEC and Ripple jointly dropped their appeals, ending the case with a $125 million penalty left in place.
A couple years later, Ripple was telling the California State Assembly that we don’t need bitcoin. pic.twitter.com/rjRdPdGCo2
— Kyle Torpey (@kyletorpey) January 24, 2025
Bitcoiners have also ridiculed Ripple for perceived marketing attacks on Bitcoin. Larsen, then Ripple’s chief executive, previously testified before a California State Assembly committee in 2015, on a panel about virtual currency that also included Coinbase and Coin Center. “We don’t believe the world needs another currency,” he said.
In 2022, Larsen’s climate foundation was the initial funder of the Change the Code, Not the Climate campaign, which pressured Bitcoin to abandon proof of work and later spawned the laser-eyed Skull of Satoshi sculpture. After Ripple donated the skull to the Bitcoin community in 2025, Larsen distanced the company from the effort. “The campaign didn’t work, and that’s ok! Note – Ripple did not fund this campaign,” he wrote.
Notably, Matt “Fortune Favors the Brave” Damon is scheduled to make his return to crypto at a Ripple event later this month, in a continuation of the longstanding tradition of reputation laundering in crypto.
Not the First Money-Printing Exploit
Crypto has a long, storied history when it comes to bugs that could allow an attacker to print money out of thin air. In 2010, a Bitcoin overflow bug created more than 184 billion bitcoin in one transaction before a fix arrived within hours and the chain was forked to erase it. In 2018, Bitcoin Core developers quietly patched a critical inflation vulnerability, at first disclosing it only as a denial-of-service bug.
Zcash covertly fixed a counterfeiting bug in 2018, and June’s flaw required an emergency soft fork and then a hard fork. The Zcash Foundation saw no evidence of unauthorized value creation, but Zcash’s shielded pool can’t be transparently audited like Bitcoin. The Liquid Network’s attackers last month kept 598.5 bitcoin and demanded a 10% bounty via messages posted directly to the Bitcoin blockchain.
Crypto’s AI Problem
At the same time, AI-powered bug hunting has sent a chill through the industry. Indeed, Taylor Hornby found the Zcash bug from earlier this year working with Anthropic’s Opus 4.8 model.
Just this past Wednesday, Ethereum Foundation researcher Justin Drake suggested AI could break Bitcoin’s ECDSA signatures in a matter of months, a claim Bitcoin experts have widely disputed. In May, OpenZeppelin co-founder Manuel Aráoz said he considers all of DeFi unsafe. “Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds,” he explained.
The disclosure report credits Liao alongside Veria AI, a product of Veria Labs, the startup he co-founded. “Veria AI is an autonomous pentester: it maps your entire attack surface, proves real exploits, and drafts the fix,” the company’s website says. Neither has said how the XRPL bug was found, but Veria has previously written about how its AI found a proof forgery bug in the Aleo blockchain that earned a $65,000 bounty.
Bitcoin and crypto exploits have become more problematic in recent months, as hardware wallets, the gold standard for self-custody and offline storage, have come under attack. A firmware flaw in Coinkite’s Coldcard hardware wallets let attackers drain over $100 million in bitcoin in July, and on Friday, Ledger began investigating drained funds from devices sold by an authorized Southeast Asian reseller, in a suspected supply chain attack.
After its bug was disclosed in June, Zcash’s ZEC fell about 60% in a couple of days, but XRP hasn’t moved much since this latest bug was revealed.
Click Here For The Original Source.
