A Ripple engineer says AI makes critical security flaws easier to find and exploit. The warning follows disclosure of an XRP Ledger bug that could have let attackers mint trillions of XRP. The developers report no evidence of exploitation on the public network.
Mayukha Vadari, an engineer with RippleX, warned about growing security threats as AI spreads. The warning came after developers identified a critical vulnerability in the XRP Ledger (XRPL) that would have let attackers mint trillions of XRP from thin air.
According to Vadari in a post on X: "You can't just sneak in a critical bug patch in a regular public release process".
How the XRP Ledger bug worked
Veria AI identified the vulnerability on Sept. 21. Veria Labs developed the AI-based security system. Researchers filed a bug report through the XRP Ledger bug bounty program the next day.
Veria Labs said the flaw would have allowed 18.45 trillion XRP to be minted in a single transaction, over 184 times the initial supply. Researchers believed it could have affected XRP's entire market cap, which they estimated at around $94 billion when they filed the report.
According to the official disclosure, the cause was an integer overflow in the XRPL payment engine. The code dated to 2015 and handled payment amounts across multiple offers on the decentralized exchange.
Under certain circumstances, an attacker could create hundreds of specially crafted offers with abnormally high XRP values. If processed as a group, their combined amount could overflow the system's 64-bit integer calculations. The result would be a much lower figure, so sellers could receive the full amount of XRP while the buyer paid a minuscule fraction.
Emergency update released without source code for now
The team released an emergency update, xrpld 3.4.1, on Sept. 25. However, it has kept the source code with the security fixes unpublished for now.
Some in the crypto community have criticized the move, questioning whether sharing binaries without publishing the code fits the network's open-source nature. The developers, meanwhile, have found no evidence of exploitation on the public network.
Source: U.Today
Trading involves risk.