YouMind
تسجيل الدخول

The Biggest Hack in Crypto History That Never Happened

@Cayden_Liao
الإنجليزية11 أكتوبر 2026
251K
1.8K
252
169
870

ليرة تركية؛ د

Veria Labs' AI discovered a severe, decade-old vulnerability in the XRP Ledger that allowed infinite token minting, threatening its $94B market cap. The bug was patched rapidly, earning the team a record $250,000 bounty.

Last month, our AI discovered a vulnerability that let anyone mint infinite tokens on XRP.

XRP is the fifth-largest cryptocurrency, bigger than Solana and USDC, with a $94B market cap. Released by @Ripple in 2012, it is also one of the oldest blockchains.

$94 billion at risk

XRP launched with a fixed supply of 100 billion tokens. You can't mine or stake on the network, and each transaction burns a small fee, so the coin's supply should only ever go down.

The bug we found allowed any unauthenticated attacker to create 18 trillion XRP with a single transaction, 184 times the total supply.

This puts the full $94B at risk, more than 60 times the largest crypto hack on record (Bybit, $1.5B).

To our knowledge, no whitehat has ever found a bigger vulnerability. The previous record we know of was a 2021 bug affecting $24B on Polygon.

A decade-old bug

This bug has been live on the XRP Ledger for nearly a decade, introduced in code written in 2015 and 2017.

This is one of the most heavily reviewed codebases in crypto and has survived some of the heaviest scrutiny. The XRP Ledger has paid out well over $1M in bug bounties and has had more than a dozen audits and audit contests since 2024 alone, including one contest with a $550K prize pool.

We suspect one reason nobody caught this vulnerability is that it chains together two bugs that would be low severity on their own.

How our AI found it

We pointed our agent at rippled, the software that runs the XRP Ledger. It found both bugs, worked out how to chain them together, and built a working exploit on a local network to prove it.

It flagged the bug at 11:56 pm on a Monday. I didn’t believe it, so I read through the proof of concept three times.

By 4 am I still couldn’t find anything wrong with it, so I woke up our founding engineer to go through it with me. Vulnerabilities directly affecting $94B don’t come along often. Neither of us could believe one had been sitting in XRP for nearly a decade without anyone noticing.

By morning we were sure it was real.

The Veria agent hunts not only for the highest-impact bugs, but also for how lower-severity vulnerabilities can be chained into something much worse.

After we disclosed the vulnerability, we tried pointing both Astra and Mythos directly at the vulnerable code, and they still couldn't find it.

Patched in three days

We reported it through XRPL's bug bounty program, and their team moved quickly.

  • Sept 22: reported and confirmed on the same day
  • Sept 23: fix merged
  • Sept 25: fix released, with over 80% of validators upgraded.

Normally, changes to how the XRP Ledger processes transactions go through an amendment process, where validators vote over about two weeks.

For the first time in more than ten years since introducing that process, XRPL skipped it and shipped an emergency fix, because, as their disclosure report put it, "an attacker could have created spendable XRP far beyond the total supply."

RippleX found no evidence it was ever exploited. We thank the RippleX team for their quick response and triage and want to give a sepcial shoutout to @ja_akinyele and @sappenin.

We only wish the same could be said for some of the other projects we have reported similarly impactful vulnerabilities to (besides the goats at Provable) 🫠

The largest AI bug bounty

The Ripple team awarded us the maximum $250,000 bounty offered by their bug bounty program. To our knowledge, that's the largest ever paid out for a vulnerability discovered entirely by an AI agent.

AI cuts both ways

Earlier this summer, an attacker drained 1,367 BTC ($89M) from Coldcard wallets through a bug that had been sitting in firmware for five years, and it's likely that AI played some part in that attack.

AI is making old bugs much cheaper to find, and attackers have access to the same tools you do. Even a codebase as heavily audited as the XRP ledger had a critical vulnerability hiding in it for a decade.

Fortunately, there's far more good hackers than bad ones. We discovered the XRP bug, and the RippleX team responded promptly to fix it before anyone could use it.

As long as defenders adopt these tools as fast as attackers do, the good guys have the upper hand.

We work with teams like Phantom, Tempo, and Provable to find these bugs before attackers do. If you want us to look at yours, DM me.

And if there's a codebase you think we should point at next, tell me in the replies.

Full technical write-up and PoC below. 👇

بنقرة واحدة حفظ

استخدم YouMind للقراءة العميقة للمقالات سريعة الانتشار بتقنية الذكاء الاصطناعي

احفظ المصدر، واطرح أسئلة مركزة، ولخص الحجة، وحوّل المقالة واسعة الانتشار إلى ملاحظات قابلة لإعادة الاستخدام في مساحة عمل واحدة تعمل بالذكاء الاصطناعي.

اكتشف YouMind
للمبدعين

حول Markdown إلى مقالة 𝕏 نظيفة

عندما تنشر كتاباتك الطويلة، فإن الصور والجداول وكتل التعليمات البرمجية تجعل تنسيق 𝕏 مؤلمًا. YouMind يحول مسودة Markdown كاملة إلى مقالة نظيفة وجاهزة للنشر 𝕏.

حاول Markdown إلى 𝕏

المزيد من الأنماط لفك التشفير

المقالات الفيروسية الأخيرة

استكشاف المزيد من المقالات الفيروسية