RippleX says critical XRPL flaw could theoretically have enabled excess XRP creation, now patched

RippleX says critical XRPL flaw could theoretically have enabled excess XRP creation, now patched

N
News Editor
2026-10-11 02:24:36
RippleX engineering lead J. Ayo Akinyele said in a post on X that the company is treating a recently disclosed vulnerability in the XRP Ledger’s payment engine as a serious security issue. According to his statement, the bug had been present in the codebase for more than a decade and, in theory, could have allowed XRP to be created beyond the network’s fixed supply cap. He added that the flaw was discovered before any exploitation took place by security research firm Veria AI through Ripple’s bug bounty program. Akinyele said Ripple quickly developed and tested a fix, then worked closely with validators to complete a network upgrade before the vulnerability was publicly disclosed. He also said AI is changing the speed of vulnerability discovery, which means XRPL needs stronger security response capabilities. Looking ahead, RippleX plans to expand its bug bounty efforts, increase AI-assisted vulnerability hunting and adversarial testing, review long-standing code in the payment engine, consensus mechanism and P2P network, and push formal verification for critical modules. The stated goal is not only to patch one issue, but to identify and remove latent risks in older XRPL code and make the network harder to attack.

RippleX engineering lead J. Ayo Akinyele said on X that the company is placing high priority on a recently disclosed critical vulnerability in the XRP Ledger (XRPL) payment engine.

He described the issue as a serious security flaw that had existed in the codebase for more than 10 years and could, in theory, have allowed XRP to be created in excess of the network’s fixed supply cap.

Akinyele said the bug was discovered before it could be exploited by security research firm Veria AI through Ripple’s bug bounty program.

Fix completed before public disclosure

According to Akinyele, Ripple quickly developed and tested a patch, then worked closely with validator nodes to complete a network upgrade before the vulnerability was publicly disclosed.

He also said AI is changing the speed of vulnerability discovery, and that XRPL needs to improve its security response capacity.

RippleX outlines next security steps

RippleX plans to strengthen its bug bounty program, expand AI-assisted vulnerability discovery and adversarial testing, and review long-standing code across the payment engine, consensus mechanism and P2P network, he said.

The company also plans to advance formal verification for critical modules and reduce potential risk through broader security hardening. Akinyele said the goal is not just to fix a single bug, but to identify and eliminate latent risks in older XRPL code so the network becomes harder to attack.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
900

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.