RippleX engineer Mayukha Vadari has raised concerns about new security threats facing cryptocurrencies as artificial intelligence rapidly advances. The warning follows the disclosure of a critical vulnerability in the XRP Ledger (XRPL) that exposed the network to a risk of unauthorized minting of trillions of XRP tokens.
AI exposes new risks in blockchain security
Vadari shared insights on X, stressing that artificial intelligence tools now make it much easier for attackers to detect, reverse-engineer, and exploit vulnerabilities in blockchain systems. He noted, “Things have changed with AI. You can’t just sneak in a critical bug patch in a regular public release process, because you’re going to get caught and reverse engineered right away.”
His comments follow the public disclosure of a major bug that had been lurking in the XRP Ledger for nearly a decade. The flaw, once triggered, could have severely disrupted XRP’s ecosystem by enabling the creation of new tokens far beyond the platform’s fixed supply of 100 billion XRP.
Vulnerability discovered and reported
The vulnerability was uncovered on September 21 by Veria AI, an artificial intelligence-based security solution from Veria Labs. On the following day, their researchers filed a bug report with the XRP Ledger bug bounty program.
According to Veria Labs, this security flaw could have allowed a single transaction to mint up to 18.45 trillion XRP. This figure is more than 184 times the original total supply authorized by the network.
If exploited, attackers could have distributed the newly minted XRP by transferring it to various exchanges, threatening the integrity of the entire market capitalization, which researchers estimated at $94 billion when the bug was disclosed.
Mini dictionary: Veria AI — An advanced, AI-powered security system developed by Veria Labs, specializing in proactive threat detection and vulnerability assessment in blockchain networks.
To date, XRPL developers have not identified any evidence indicating that the bug was exploited on the public blockchain.
How the bug worked
The issue originated in code introduced to the XRPL in 2015. It affected how the ledger processed multiple offers for XRP trades on its decentralized exchange. Specifically, the flaw enabled attackers to create hundreds of abnormal trading offers with exaggerated XRP values.
If these offers were processed together, the system’s 64-bit integer calculations could overflow. Instead of flagging the error and rejecting the transaction, the network would underestimate the total payment amount, crediting sellers with the intended value while charging the buyer only a tiny fraction.
| Affected Feature | Year Introduced | Potential Impact (in XRP) | Real Exploitation Evidence |
|---|---|---|---|
| Multi-offer payment calculation in DEX | 2015 | 18.45 trillion XRP | No |
Even the XRPL’s native safeguards, designed to prevent the unauthorized creation of new XRP, were vulnerable due to similar calculation errors.
Emergency update and open-source concerns
In response, the XRPL development team opted for an unusual remediation approach. On September 25, they released an emergency update labeled xrpld 3.4.1. Notably, the source code for the fix has not been made public immediately. Developers have withheld the code to prevent potential exploitation while networks update their nodes.
This strategy has prompted criticism from some quarters of the cryptocurrency community, as it temporarily restricts access to the source code. Detractors have argued that limiting code transparency conflicts with the open-source principles on which XRPL was built, even if it aims to protect the network from attack during critical periods.
Artificial intelligence has shifted the landscape for blockchain security, making it harder to quietly patch critical vulnerabilities. Developers have urged that swift, but sometimes controversial, action is necessary to safeguard crypto assets against ever more sophisticated threats.




