AI Uncovers XRP Ledger Bug: Is It a Threat or a Defense?
An AI security system just flagged a flaw in the XRP Ledger that human reviewers missed for a decade, and the fix required breaking a decade-long protocol. Now developers across every major crypto network are asking whether AI accelerates their…
This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.
A recent discovery by Veria Labs, a security firm, revealed a major flaw in the XRP Ledger that could have created an astounding 18.45 trillion XRP (CRYPTO: XRP) out of thin air. This amount is more than 184 times the original total supply of 100 billion XRP coins. Veria Labs warned that this bug posed a serious risk to XRP’s entire market value, which stood at about $94 billion at the time of the report.
On September 22, 2026, researcher Cayden Liao, together with Veria AI, an artificial intelligence security system, identified this vulnerability. The issue stemmed from a single payment that could buy multiple trading offers at once. A counting error let sellers receive full payment while the buyer was charged almost nothing, creating XRP that never actually existed. Unfortunately, the safety check designed to detect such errors failed because of the same faulty counting code.
RippleX, Ripple’s engineering division, said it found no evidence the bug was exploited. Nevertheless, AI’s role in pinpointing the bug prompted engineers to revise their approach to releasing fixes for such vulnerabilities.
This revision affects not only XRP holders, with their digital asset trading around $1.39, but also investors in Bitcoin (CRYPTO: BTC), priced at about $82,965, and Ethereum (CRYPTO: ETH), trading at around $2,501. With that in mind, the question is: Is AI a significant threat to crypto, or is it becoming its best defense?
AI Found an XRP Ledger Flaw Human Reviewers Missed for a Decade

AI has identified a flaw that human reviewers missed for a decade, and the researcher who found it was paid to look. Cryptocurrency networks often run bug bounty programs that reward outside researchers for finding vulnerabilities before malicious actors can exploit them. In this case, the bounty system worked as intended, leading to a swift report of the flaw to those able to resolve it.
Engineers reproduced the bug the same day it was reported and patched it within three days. Over 80% of trusted validators, the computers that verify XRP Ledger transactions and ensure accurate records, implemented the patched software on its release day.
The XRP bug adds to a series of long-hidden security weaknesses in the crypto world that AI has helped uncover since July. Several of these discoveries have also involved Bitcoin. For instance, a flaw in the Coldcard wallet, which is a hardware device that secures Bitcoin keys offline, has been linked to the theft of at least 1,367 Bitcoin. Additionally, Core Lightning, software that accelerates Bitcoin transactions, advised operators to disconnect after similar vulnerabilities were discovered.
Although the Coldcard theft is unfortunate, these revelations bring previously concealed issues to light, allowing developers to address them. This suggests AI is bolstering defenses by clearing a backlog of vulnerabilities before attackers exploit them.
Fast XRP Ledger Fixes Expose Bitcoin’s Slow Upgrade Process

RippleX engineer Mayukha Vadari shed light on the decision to bypass the XRP Ledger’s usual release process for the patch. “Things have changed with AI. You can’t just sneak in a critical bug patch in a regular public release process, because you’re going to get caught and reverse-engineered right away,” Vadari stated.
Attackers can compare new code with the old to pinpoint what has been fixed. Once a patch is public, anyone can do this analysis and see where to target unpatched systems. While this has always been true, machines now perform these comparisons much faster.
In response, XRP Ledger developers released binaries—ready-to-run program files—prior to sharing the underlying source code. This marked the first time a transaction-processing change was issued without passing through the amendment voting process that has governed such updates for over a decade. XRP had this speed advantage because developers could quickly mobilize a small group of trusted validators.
In contrast, Bitcoin lacks a similar system. Its rule changes go through public proposal processes that can take years to finalize, since no node operator can be forced to upgrade. This slow approach safeguards holders from a single group altering the rules, but it also makes the network less agile in fixing issues. Ethereum falls somewhere in between, needing many independent operators to install new software to implement upgrades.
The quick fix to the XRP bug has reignited the debate about transparency. Validators initially ran a program outsiders couldn’t inspect, raising concerns about whether the network remains open-source, as many assume. The code was shared later, but holding it back temporarily denied attackers a clear path to unpatched systems.
Moreover, this issue extends to the cryptographic math that underpins every digital wallet. Justin Drake of the Ethereum Foundation has suggested that AI-driven mathematical advancements could pose a more immediate threat to the cryptography securing these networks than quantum computers. Michael Gutkin of Fireblocks countered that researchers have not yet demonstrated a breach of this cryptography. The ongoing debate centers on AI’s implications for the development and security of crypto technologies.
Is AI Crypto’s Biggest Threat or Its Best Defense?
For now, AI looks like a net defense. Since July, researchers have reported the flaws it surfaced, and the XRP Ledger fix reached validators before anyone exploited the bug.
The weak spot is the gap between a public patch and enough nodes installing it, and Bitcoin has no small group to upgrade overnight. If attackers exploit a major network inside that gap, AI could start to look like a threat.
Contact [email protected] for any questions or corrections.








