A flaw in the XRP Ledger’s payment engine, present since the engine was written in 2015, could have let an attacker create XRP from nothing, according to a disclosure report the ledger’s developers published on 9 October. The report credits “Cayden Liao and Veria AI, for the original XRP overflow report and proof of concept”. The fix shipped in xrpld 3.4.1, and the report says “We have found no evidence that this issue was exploited on any public network.”
Veria Labs says its AI agent found the bug and built a working exploit, and that it was awarded the program’s maximum $250,000 bounty. To ship the fix, the developers skipped the validator vote, known as the amendment process, that normally gates rule changes. The report calls it “the first time a change to transaction processing has deliberately shipped this way since the amendment system was introduced more than ten years ago.”
What the Bug Did
The report says the overflow sat where the payment engine adds up what a single payment owes across many offers on the ledger’s order book. That sum “used plain 64-bit integer addition with no overflow check.”
Pushed past its maximum, the total wrapped around to a small number. In the report’s words: “The engine paid each offer owner their full amount individually but charged the buyer only the wrapped-around total. The difference was new XRP that should never have existed.”
The ledger also runs a safety check that no transaction creates XRP. According to the report, “that check summed balance changes the same way, so it wrapped around identically and detected nothing.” It says the check was added two years after the payment engine and “was built on the same unchecked arithmetic.”

Business Pill · A SANITY CHECK
A one-minute explainer of a sanity check: take the numbers you were given and do the sum yourself, because small items can add up to a very different total. It teaches the general idea only and says nothing about any person or organisation in this story.
The key insight: As we read it, the report answers two questions the coverage ran together: who found the bug, and why the fix could not wait for a vote. On the second, its answer is that an open-source fix reveals the bug it fixes, so a patch waiting weeks for activation would have pointed attackers at a live flaw.
What an Attack Would Have Taken
The report puts the attacker’s real cost at “a few hundred XRP in account and offer reserves” plus ordinary transaction fees, and says “The attack did not need a large starting balance.”
It could not have happened by accident, the report says: it “required hundreds of offers priced in a way no real trader would use, followed by a payment built specifically to consume them all at once.”
The disclosure describes the result as spendable XRP “far beyond the total supply in a single validated transaction.” Veria’s write-up gives the size: one trigger using 256 offers would credit about 18.45 trillion XRP, spread across 256 accounts, and the setup could be repeated. Veria calls that “184 times the total supply”; XRP launched with a fixed supply of 100 billion tokens.
How the AI Was Involved
Veria’s post, signed Cayden and dated 10 October, opens: “Last month, our AI discovered a vulnerability that let anyone mint infinite XRP.” It says the team pointed its agent at rippled, the software that runs the ledger, and “It found both bugs, worked out how to chain them together, and built a working exploit on a local network to prove it.”
Its timeline has the agent identifying the mint on 21 September and building the proof of concept on 22 September, the day “Cayden validates the PoC and confirms the bug is reachable on mainnet” and the report went in.
Veria also says that after the disclosure it “pointed general-purpose coding agents directly at the vulnerable code, and they still couldn’t find it.” The XRPL report credits Cayden Liao and Veria AI jointly, and says the submission rated the finding Major before RippleX engineers raised it to critical.

Why the Fix Skipped the Vote
Rule changes on the XRP Ledger normally ship switched off. The report says a change “turns on only after it has kept the support of more than 80 percent of trusted validators for two weeks.” This fix instead took effect on each server as soon as that server upgraded.
The report gives the reason: “xrpld is open source, so any release containing the fix also shows where the bug is.” Under the normal process, it says, “the bug would have been both visible and still exploitable on Mainnet.”
It says more than 80 percent of validators on the default UNL, the list of trusted validators, were running 3.4.1 on its release day, 25 September, “even though the source code for the fix was not yet published.” It adds that the case “does not change how the XRP Ledger makes protocol changes.”
A Second Bug in the Same Report
The report also covers a separate flaw in the Batch feature, which lets one account submit up to eight transactions as a single unit. It was first reported as finding F48 in the Sherlock Attackathon and rated low severity, then found to risk a consensus split between server versions.
Batch had not been activated on Mainnet, and the report says no Mainnet accounts or funds were affected. That fix, fixBatchV1_2, activated on Mainnet on 9 October.
What the Bounty Shows
Veria says: “We were awarded the maximum $250,000 bounty offered by XRPL’s bug bounty program.” It adds: “To our knowledge, that’s the largest ever paid out for a vulnerability discovered entirely by an AI agent.”
The XRPL report describes its defence model as layering “independent audits, public attackathons, AI-assisted red teaming, fuzz testing, and formal verification on top of the bug bounty.” It says every security finding marked as fixed, “regardless of source (including audits, bug bounties, and AI red-teaming)”, will now be re-tested against the release candidate.
Veria’s own conclusion: “AI is making old bugs much cheaper to find, and attackers have access to the same tools you do.”
The Structural Read
The bug lasted because the check meant to catch it was built from the same arithmetic. The report says the “no XRP created” invariant summed the net change “using the same kind of 64-bit counter”. As we read it, that is a sanity check that shares the failure of the thing it checks.
Each offer was valid on its own; only the total broke. The report says “no normal payment comes anywhere near a 64-bit overflow”, which is why reaching it took a deliberately built set of hundreds of offers.
The two documents line up on how the finding arrived: Veria says its agent built a working exploit on a local network, and the report says RippleX reproduced the mint on 22 September, the day it was reported. As we read it, a finding that comes with a proof of concept is cheap for the defender to check.
XRPL disclosure report for xrpld 3.4.1, 9 October 2026
“In this case, a network halt would actually be preferable to processing exploit transactions and creating an incorrect ledger state that would be hard to roll back.”
Three Implications
LEDGER OPERATORS The report says all server operators must upgrade to 3.4.1 or newer to stay in sync with the network, and that older servers are now amendment blocked.
SECURITY TEAMS The report adds a re-verification step: a finding marked as fixed is closed only when the release candidate passes a test that reproduces the original reported issue.
AI SECURITY VENDORS Veria says it was awarded the program’s maximum bounty, which it calls, to its knowledge, the largest ever paid for a vulnerability discovered entirely by an AI agent.
The Business Engineer Lens
This story maps onto the Business Engineer framework The Agentic Harness War.
The analysis expects that “Universal harnesses are likely to dominate highly digital, modular, and verifiable work.”
As we read it, a bug hunt that ends in a working exploit is that kind of work: the proof of concept either mints XRP on a local network or it does not, which is how RippleX could reproduce it the day it was reported.
What Is Not Established
The 18.45 trillion figure, the $250,000 award and the account of an AI agent finding the bug on its own are Veria’s statements. The XRPL report confirms the joint credit to Cayden Liao and Veria AI, the bug, the fix and the dates.
We have not run the proof of concept. The report says RippleX engineers reproduced the mint on a local standalone server, and that it found no evidence the issue was exploited on any public network.
The Bottom Line
A flaw present since 2015 in the XRP Ledger’s payment engine was reported with a working exploit on 22 September, fixed in xrpld 3.4.1 three days later and shipped without the usual validator vote, which the developers call a first in more than ten years. Veria says its AI agent found the bug; the ledger’s report credits Cayden Liao and Veria AI together.
95,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.
A note on sourcing. On 11 October 2026 we read in full the XRP Ledger’s Vulnerability Disclosure Report for xrpld 3.4.1, published on 9 October, and Veria Labs’ own post of 10 October; CryptoSlate’s report pointed us to Veria’s post. Figures on the size of the mint and the bounty are Veria’s. We have not run the proof of concept. Nothing here is investment advice.
Sources: XRP Ledger, Vulnerability Disclosure Report for xrpld 3.4.1 (9 Oct 2026) · Veria Labs, The Biggest Hack in Crypto History That Never Happened (10 Oct 2026) · CryptoSlate report (11 Oct 2026), which pointed to Veria’s post







