Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
XRP Ledger Patches Decade-Old Bug That Could Have Let Attackers Mint XRP

A bug that may have been in the XRP Ledger's code since 2015 could have let an attacker create XRP out of nothing and spend it. It has been fixed. The disclosure was published Friday, Oct. 9, about two weeks after the patch went out.
The XRP Ledger was built with a fixed supply. All 100 billion XRP were created at launch in 2012, and the software is designed so no more can ever be added. This flaw threatened that rule directly.
How the flaw worked
The vulnerability is an integer overflow in the ledger's payment engine, according to the disclosure. It runs through the built-in exchange, where accounts post offers to swap one token for another.
An attacker would open hundreds of accounts. Each would offer a tiny amount of a token in exchange for an unusually large amount of XRP. Then the attacker would send a single payment that bought every offer at once.
The total XRP owed came out too large for the software to count correctly. The selling accounts were paid in full, while the buying account was charged almost nothing. The attacker ended up holding XRP that had not existed before.
The ledger runs a check after every transaction to confirm no new XRP has appeared. That check relied on the same miscounted total, so it would have missed the attack. A separate cap on how much XRP a single account can receive would not have triggered either, because the XRP was spread across hundreds of accounts.
The disclosure says the minted amount could potentially far exceed the total supply.
Cost and timeline
The method needed only a few hundred XRP to open the accounts, most of which could be recovered, plus transaction fees. The security report says that is a low barrier for an attack of this size.
Researcher Cayden Liao and Veria AI found the flaw, according to the report. It was submitted through the bug bounty program on Sept. 22. Engineers at RippleX, Ripple's developer arm, reproduced the attack on a standalone server and confirmed the newly created XRP could be spent in a later transaction.
Developers released the fix in xrpld 3.4.1, the ledger's server software, on Sept. 25. That is three days after the report. The release did not say what it repaired.
RippleX said it found no evidence the flaw was exploited on any public network.
Ripple's wider security push
Separately, Ripple has described an overhaul of how it secures the ledger. It is building AI tools into code reviews, threat modeling and adversarial testing. The company says it has moved from reactive debugging toward continuous vulnerability hunting.
A dedicated red team has already found more than 10 bugs, though only lower-severity findings have been disclosed. One of those involved the proposed XLS-68 Sponsor amendment. It could have allowed unbacked ledger objects under certain conditions, was caught in Devnet testing, and was fixed in xrpld 3.4.0 before the amendment could activate on the main network.
The red team is focused on how the older XRPL architecture interacts with newer features. The network is adding institutional lending, tokenization, advanced permissions and support for institutional financial products. Proposals are also under discussion that could eventually let XRP serve as collateral for institutional credit.
New features do not go live automatically when software ships. Proposed changes have to pass through the network's decentralized amendment process, where validators vote.
What the fixed-supply rule means
The fixed supply is the selling point for institutions that use the network. An attacker who could create XRP and sell it on exchanges would undercut that cap, which is why the bug counts as critical rather than cosmetic.
The flaw came out of a bug bounty submission, and no exploitation has been detected. How long a flaw sat in widely used code before anyone found it is a separate matter, and the disclosure puts that figure at roughly a decade.
The case also shows researchers using AI tools to find old flaws in blockchain code. Veria AI is credited alongside Liao in the report.
What comes next
Ripple says it plans to require multiple independent audits for significant amendments. It also plans expanded bug bounties and "attackathons," or organized adversarial testing events. Those rules will apply as the ledger takes on the lending and tokenization features that make its code more complex.
RippleX has not said how many server operators have upgraded to xrpld 3.4.1.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.