Article

Cybersecurity
CISO-as-a-service consulting: posture, remediation roadmap, ongoing support.
Discover →CyberAgent
Continuous vulnerability assessment and gap analysis: scanning, mapping onto framework requirements, documentary evidence ready to use.
Discover CyberAgent →On 9 October XRPL published the report on two vulnerabilities fixed in xrpld 3.4.1, the XRP Ledger node software. The more serious one is an overflow in the payment engine that could have created spendable XRP. The report calls it critical if exploited and adds: “We have found no evidence that this issue was exploited on any public network”.
Veria Labs told the story of the discovery on its blog under the title “The Biggest Hack in Crypto History That Never Happened”. Nothing was stolen: this is a vulnerability reported and fixed before any known exploitation.
The bug
When a payment consumes several order book offers, the payment engine adds up the XRP amounts. The sum used a 64-bit integer with no overflow check: past the maximum value, the total wrapped around to a small number. As a result offer owners were paid in full while the payer was charged only the wrapped total.
There is a check, the “no XRP created” invariant, designed precisely to prevent XRP creation. It used the same unchecked arithmetic and so did not notice.
According to Veria’s reconstruction, about 256 funded accounts with their offers were enough, with no privileges on validators. The XRPL report confirms that the attack was cheap: the main cost was reserves and fees. According to the report the bug had probably been present since 2015, when the current payment engine was written; Veria dates the invariant to February 2017.
The fix without an amendment
- 22 September: report through the XRPL bug bounty, credited to Cayden Liao and Veria AI. The reporter rated it Major; RippleX raised it to critical after reproducing it.
- 25 September: emergency release of xrpld 3.4.1. The same day more than 80% of the default UNL validators had upgraded.
- 9 October: publication of the report.
The fix adds an overflow check to the sum of offers and a wider counter in the invariant. It took effect as nodes upgraded, without an amendment vote, the procedure that normally takes weeks. XRPL explains the choice with severity: xrpld is open source, and publishing the fix would have revealed the bug for the whole activation period. The report adds that halting the network would have been preferable to processing exploit transactions.
The role of AI
The XRPL report credits the finding to Cayden Liao and Veria AI but does not say how it was found. The rest comes from Veria. According to the company, its AI agent identified the two flaws and built a proof of concept on a local network, which a person then validated. Veria also writes that, after the disclosure, general-purpose coding agents pointed directly at the vulnerable code could not find it. It also states a bounty of $250,000. These are the company’s claims, not independently verified.
What follows
For cybersecurity. A bug that stayed hidden for about ten years, in code that according to Veria has had more than a dozen audits and audit contests since 2024 alone, surfaced through AI-assisted analysis. Veria draws the thesis that AI makes old bugs cheaper to find, for defenders and attackers alike. On a single case it remains an indication, consistent with what model vendors claim: Google, too, presents the capabilities of Gemini 4 Argon as a tool for defenders.
For anyone writing financial software. The error is arithmetic: a sum of amounts exceeding the capacity of the data type. The case shows two things:
- a security check only protects if it does not share the flaws of what it checks: here the invariant and the main code used the same arithmetic;
- stopping on error limits the damage. Veria notes that compiling with overflow trapping would have turned the bug into a node crash: an outage instead of value creation.
For crypto and fintech infrastructure. In an open-source project the fix itself reveals the problem, and the speed at which nodes upgrade becomes part of security. Here more than 80% of the default UNL validators had upgraded on release day. Since 9 October, with the activation of fixBatchV1_2 (the amendment fixing the report’s other bug), nodes older than 3.4.1 are blocked and no longer stay in sync with the network.
What remains uncertain
- How much of the discovery is due to the AI agent and how much to human work: the official report does not say.
- The value at risk: Veria’s figures (the whole XRP market cap) are the company’s estimates.
- The status of networks derived from the xrpld code: postfiatd merged the fix on 10 October; for the others there is no public information.
What to watch
- Further bug bounty reports attributed to AI tools, with verifiable descriptions of the method.
- Upgrades of networks and services built on the xrpld code.
- How open-source projects handle emergency fixes when the patch reveals the bug.
