Researchers showed how bad actors could generate spendable XRP through unbacked payments, which triggered an urgent software release.
A security report released Friday revealed that a glitch in the XRP Ledger’s payment process allowed exploits to forge vast sums of XRP freely, violating the token’s strict supply limit.
Cayden Liao and Veria AI uncovered the nearly decade-old flaw on Sept. 22, before RippleX engineers verified that newly created XRP could be spent in subsequent transactions.
RippleX confirmed that no evidence was found indicating attackers ever leveraged the vulnerability across any live network.
The entire 100-billion XRP supply originated at the ledger’s 2012 launch, governed by strict code that prevents further creation; however, this exploit threatened to let bad actors generate fake tokens and dump them on exchanges, undermining the supply cap institutional users rely upon.
Exploits targeted the ledger’s integrated order book, where users place offers that are designed to trade one token against another.
In theory, a bad actor could launch hundreds of profiles, set each to swap tiny token amounts for massive XRP sums, then initiate a single transfer through which every order was swept up simultaneously.
Stay in the loop
Get crypto news before the market moves
Join thousands of investors who read our daily briefing.
No spam. Unsubscribe anytime.
Because the total XRP owed would exceed what the system can process accurately, full payouts were credited to the seller’s profiles while charging the buyer practically zero—granting the actor newly minted tokens out of thin air.
XRP Ledger’s Validation System Could Have Missed Unauthorized Token Creation#
Although the XRP Ledger verifies every transaction to prevent unauthorized token creation, it relied on the glitched calculation and failed to spot the anomaly; meanwhile, spreading the newly generated XRP across hundreds of profiles bypassed individual balance caps that were configured to flag suspicious activity.
Executing this strategy required just a few hundred XRP to establish the necessary accounts—most of which could be reclaimed—alongside standard network fees that were incurred during processing.
Engineers deployed the patch in server update xrpld 3.4.1 on Sept. 25 while keeping details hidden regarding what was fixed.
This event adds to a series of dormant crypto flaws exposed with AI assistance since July—including the Coldcard wallet glitch linked to the theft of 1,367 BTC and security breaches that were flagged, forcing Core Lightning to advise node operators to go offline.



