BREAKING
Oct 11For 11 Years, a Few Hundred XRP Could Have Printed XRP Past the 100 Billion Cap. Ripple's Engineers Patched It Without Telling Anyone Why●Oct 10Ledger Just Told Buyers Not to Set Up the Wallet They Paid For. Analysts Say $86M Is Already Gone●Oct 9Cantor Fitzgerald's Tether Stake Went From $600M to $10B. Now a Senator Wants to See the Receipts●Oct 7OKX Pleaded Guilty to Running an Illegal Money Business in the US. Now Circle, Ripple and Standard Chartered Are Buying In●Oct 6Treasury Wanted a Token Swap or a Fresh Wallet Address Counted as 'Mixing.' It Just Dropped the Rule●Oct 5Someone Just Drained $6 Million From a Vault on Base. Nobody Will Say Whose Vault It Was●Oct 4Blast Pulled In $2 Billion Before It Even Had a Chain. Now It's Switching the Chain Off Because It Can't Cover the Bills●Oct 3Someone Stole Less Than $1,000 From MetaMask's Validators. MetaMask Is Pulling $1.4 Billion of ETH Out of Staking Because of It●Oct 2The SEC Just Told Fund Managers They Can Hold Your Crypto Keys Themselves. The Catch: Every Quarter They Have to Write Down That Nobody Else Will●Oct 1Two Appeals Courts Just Said Kalshi Sports Bets Are Gambling. The CFTC, Run by One Man, Is Rewriting the Dictionary So They Aren't.●Oct 11For 11 Years, a Few Hundred XRP Could Have Printed XRP Past the 100 Billion Cap. Ripple's Engineers Patched It Without Telling Anyone Why●Oct 10Ledger Just Told Buyers Not to Set Up the Wallet They Paid For. Analysts Say $86M Is Already Gone●Oct 9Cantor Fitzgerald's Tether Stake Went From $600M to $10B. Now a Senator Wants to See the Receipts●Oct 7OKX Pleaded Guilty to Running an Illegal Money Business in the US. Now Circle, Ripple and Standard Chartered Are Buying In●Oct 6Treasury Wanted a Token Swap or a Fresh Wallet Address Counted as 'Mixing.' It Just Dropped the Rule●Oct 5Someone Just Drained $6 Million From a Vault on Base. Nobody Will Say Whose Vault It Was●Oct 4Blast Pulled In $2 Billion Before It Even Had a Chain. Now It's Switching the Chain Off Because It Can't Cover the Bills●Oct 3Someone Stole Less Than $1,000 From MetaMask's Validators. MetaMask Is Pulling $1.4 Billion of ETH Out of Staking Because of It●Oct 2The SEC Just Told Fund Managers They Can Hold Your Crypto Keys Themselves. The Catch: Every Quarter They Have to Write Down That Nobody Else Will●Oct 1Two Appeals Courts Just Said Kalshi Sports Bets Are Gambling. The CFTC, Run by One Man, Is Rewriting the Dictionary So They Aren't.●
BTC -- --%
ETH -- --%
Fear & Greed F&G 61 Greed
ESC
Type to search articles
For 11 Years, a Few Hundred XRP Could Have Printed XRP Past the 100 Billion Cap. Ripple's Engineers Patched It Without Telling Anyone Why
BREAKING

For 11 Years, a Few Hundred XRP Could Have Printed XRP Past the 100 Billion Cap. Ripple's Engineers Patched It Without Telling Anyone Why

XRP’s whole monetary pitch is one number: 100 billion. All of it created at launch in 2012. No mining, no inflation, no new XRP. Ever.

On Friday, the XRP Ledger’s developers admitted that since roughly 2015, anyone who knew the trick could have broken that number in a single transaction.

The cost? A few hundred XRP in account reserves, which you get back, plus normal fees.


What Happened

On October 9, the XRPL dev portal published a vulnerability disclosure report for xrpld 3.4.1. The headline bug: an integer overflow in the payment engine that could mint XRP out of nothing.

The report rates it critical. Per the report, an attacker could have created spendable XRP far beyond the total supply in one validated transaction, and didn’t need a big starting balance to do it.

It was found by researcher Cayden Liao and Veria AI, who submitted a report and proof of concept through the XRPL bug bounty program. The bounty amount hasn’t been disclosed.

The XRPL disclosure says there is no evidence the bug was exploited on any public network.


How You Print Money on a “Fixed Supply” Chain

The XRP Ledger has a built-in DEX where accounts post offers to swap tokens. The attack used it against itself:

  1. Spin up a few hundred accounts. They can all be yours.
  2. Each one posts an offer selling a tiny amount of a token for an absurdly large amount of XRP.
  3. Send one payment that routes through every one of those offers.

When a payment eats that many offers, the engine adds up what the buyer owes using plain 64-bit addition with no overflow check. Push the total past the 64-bit limit and it wraps around to a tiny number.

So every seller gets paid in full, the buyer gets charged almost nothing, and the gap is brand-new XRP.

The ledger has safety checks for exactly this. Neither one worked:

  • The “no XRP created” invariant used the same wrapping math, so it only saw the normal fee and passed the transaction.
  • The per-account balance check only trips if a single account holds more than total supply. Spread the minted XRP across hundreds of accounts and none of them gets close.

According to CoinDesk, RippleX reproduced the attack on a standalone server and confirmed the minted XRP could be spent in a later transaction. It wasn’t just a number glitch in the logs. It was real, usable XRP.


The Silent Patch

This is where it gets interesting.

DateWhat happened
Sep 22Bug reported through bounty program, rated Major. RippleX reproduces it and bumps it to critical
Sep 22–23Fix developed privately, reviewed over several rounds
Sep 25xrpld 3.4.1 ships. 80%+ of default UNL validators upgrade the same day
Oct 9Disclosure published. Old versions are now amendment-blocked

Normally, changes to how the XRP Ledger processes transactions go through the amendment process: validators vote, and a change goes live only after holding 80% support for two weeks.

This fix skipped all of that. The report says it’s the first time a transaction-processing change has deliberately shipped outside the amendment process since amendments were introduced. It took effect as each server upgraded, and the source code was published only after the rollout.

The reasoning: the exploit was cheap and hard to undo, and a two-week public vote would have meant two weeks of a known, published, exploitable money printer. The report admits the trade-off. Servers running different versions during the upgrade could have disagreed.

Call it the right call or call it an emergency override. Either way, the XRP Ledger just showed that a core team plus a validator supermajority can push a consensus-level change in three days, then explain it two weeks later.

The same release also fixed a lower-severity bug in Batch transactions. That one sat behind the fixBatchV1_2 amendment, which went live on Mainnet on Oct. 9, and no funds were at risk.


Bad Timing for XRP’s Big Week

The disclosure lands right before Evernorth, the Ripple-backed XRP treasury company, is expected to start trading on Nasdaq as XRPN. Its debut is currently pencilled in for Monday, with roughly 473 million XRP on its books, though the date has already slipped once.

An institutional XRP vehicle going public the same week everyone finds out the supply cap was breakable for a decade. That’s going to be a fun roadshow question.


The Bigger Pattern: AI Is Digging Up Old Bodies

This isn’t a one-off. CoinDesk ties it to a run of long-hidden flaws surfaced with AI help since July, including the Coldcard firmware bug behind the theft of at least 1,367 BTC (which we covered) and vulnerabilities that led Core Lightning to tell bitcoin node operators to disconnect.

Code that survived a decade of human review is getting re-read by machines that don’t get bored. Some of those machines are working for bounty hunters. Some of them aren’t.

The XRPL team’s own takeaway says a lot: every bug marked “fixed” must now be re-tested against the release candidate and reproduce the original issue before it’s closed.


Why This Matters for Crypto Jobs

AI-assisted security research is now a real job. A researcher working with an AI tool found a critical bug in a top-10 chain’s core code that had been sitting there since 2015. Security firms, bounty platforms and protocol teams are hiring people who can point AI at old codebases and validate what comes back. Fuzzing, static analysis and formal verification skills just got more valuable.

Core protocol engineers who understand money math. This bug was unchecked integer arithmetic, one of the oldest mistakes in the book, in the hottest path on the ledger. Teams running legacy C++ chains (XRPL, Bitcoin, Lightning implementations) need engineers who can audit and harden balance-summing code without breaking consensus.

Incident response and coordinated disclosure. Getting 80%+ of validators onto a silent patch in one day takes release engineering, validator relations and comms that most chains don’t have in-house. Expect more hiring for security program managers and disclosure coordinators.

Bug bounty triage. The report came in rated “Major” and got upgraded to critical. Someone has to read these quickly and get the call right. As AI floods bounty programs with submissions, good triagers are worth their weight in XRP. The real stuff, not the wrapped kind.


The Bottom Line

The “fixed supply” was safe for 11 years mostly because nobody tried this. Now the chains that make it through the next few years will be the ones that hire people to try it first.


Want to find the next bug before an attacker does? Security researchers, protocol engineers and auditors are in demand right now. Browse open roles on Cryptogrind →

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs