Subscribe Now
Trending News

Blog Post

THEY SOLD YOU A ‘FIXED SUPPLY’ — A COUNTING ERROR FROM 2015 COULD HAVE PRINTED BILLIONS OF XRP FROM NOTHING
News

THEY SOLD YOU A ‘FIXED SUPPLY’ — A COUNTING ERROR FROM 2015 COULD HAVE PRINTED BILLIONS OF XRP FROM NOTHING 

XRP has a fixed supply of 100 billion coins. That number was never a wall. For ten years it was a promise — with a hole in it.

A security report published Friday revealed that a flaw dating back to 2015 could have let an attacker create brand-new XRP out of nothing, spend it, and dump it on exchanges. Not by hacking a wallet. Not by stealing keys. By exploiting a counting error inside the ledger’s own exchange.

Ripple’s engineers reproduced the attack on a standalone server and confirmed the freshly created XRP could be spent in a later transaction. The fix shipped quietly on September 25 in the xrpld 3.4.1 release. Nobody was told what it repaired.

So here is the question the XRP army will spend all week dodging: if a “fixed supply” can be broken by an accounting bug, what exactly have you been trusting?

What Actually Happened

The flaw was found by researcher Cayden Liao and Veria AI and reported internally on September 22, 2026. It is believed to date back to 2015. RippleX — Ripple’s developer arm — confirmed the attack worked.

The mechanic is almost beautiful in how boring it is. The XRP Ledger has a built-in exchange where accounts post offers to swap one token for another. An attacker could have opened hundreds of accounts, had each one offer a tiny amount of some token in exchange for an unusually large amount of XRP, then sent a single payment that bought every one of those offers at once.

The total XRP owed would have been too large for the software to count correctly. So the selling accounts would be paid in full — and the buying account would be charged almost nothing. The attacker walks away with XRP that never existed.

Two safety nets should have caught it. Both failed. The ledger runs a check after every transaction to make sure no new XRP has appeared — but that check relied on the same miscounted total. And the per-account limit on how much XRP one account can receive never fired, because the attack spread the coins across hundreds of accounts instead of stuffing them into one.

Total cost to pull it off: a few hundred XRP to open the accounts, plus transaction fees. Most of that was recoverable.

RippleX says it found no evidence the flaw was ever exploited on a public network. That is the good news. It is also the only reason anyone is reading this as a curiosity instead of a catastrophe.

The Silence Is the Story

Developers shipped the fix on September 25 without disclosing what it repaired. Read that again. A bug that could have printed an unlimited number of a token — one whose entire institutional sales pitch is a capped, predictable supply — was patched, and the patch notes said nothing.

You found out because a security report landed on October 9.

And this is not an isolated event. It joins a run of long-hidden crypto flaws surfaced with the help of AI since July: the Coldcard wallet bug behind the theft of at least 1,367 BTC, and the vulnerabilities that forced Core Lightning to tell node operators to disconnect. Ten-year-old bugs are falling out of the codebase like loose bricks now that machines are reading it.

Which raises the uncomfortable follow-up: how many more are sitting in altcoin codebases right now, undiscovered, on ledgers whose operators have no incentive to announce them?

Them vs Us: A Cap You Can Check vs a Promise You Can’t

Bitcoin has 21 million. Not because a company said so, and not because a whitepaper printed the number in bold. Because every full node on the planet independently validates every block against the same consensus rules, and anyone with a laptop can verify the supply themselves.

You do not have to trust a press release. You do not have to trust Ripple. You do not have to wait for a security report to find out whether the rule still holds. You run the software, you check the chain, you know.

Bitcoin has had its own supply bug, and this is where the honesty matters. In August 2010, a value-overflow error created 184 billion BTC in a single block. It was caught within hours, the code was patched, and the chain was rolled back past the bad block — openly, in public, with the whole network watching. In 2018, the duplicate-input inflation bug (CVE-2018-17144) was responsibly disclosed and patched before anyone could exploit it.

The difference is not that Bitcoin’s code is perfect. It is not. The difference is what happens next. Bitcoin’s rule changes require the network to agree, and the evidence of whether the rule held is sitting on your own machine.

XRP’s cap is enforced by a company’s software, patched on a company’s schedule, and explained in a company’s blog post — if they feel like writing one. That is not the same product. It was never the same product. The only reason you are hearing about it now is that somebody outside the company went looking.

What This Means for Your Stack

If your money is in an altcoin because a chart promised a capped supply, you have been holding a spreadsheet maintained by strangers. The number in the whitepaper is not a law of physics. It is an accounting convention enforced by code that other people write, audit, and quietly patch.

If your money is in Bitcoin, run a node. Not because it is fashionable, but because it is the only way the “21 million” claim in your head becomes a fact in your hands. Start small: a wallet you actually control, chosen deliberately instead of downloaded in a panic, then a node when you are ready.

And when you buy, buy from people who refuse to touch altcoins at all. Bull Bitcoin is Bitcoin-only — no XRP, no token of the month, no “fixed supply” that turns out to be a rounding error waiting for a researcher with an AI model. Use coupon LOVEISBITCOIN at loveisbitcoin.com/bull and keep the coins where the supply rule can be checked by you.

The Lesson

Every supply cap in crypto is either a rule your own machine can verify, or a promise from someone else. There is no third category. XRP’s promise had a decade-old hole in it, and the people who built it chose to fix it in silence.

Bitcoin’s rule is the only one you can check yourself — and that is exactly why it is the only one that has survived every bug, fork, panic, and bounty hunter thrown at it.

Here is my question for you: if a “fixed supply” can be broken by a counting error and then patched in silence, what is the number in your altcoin’s whitepaper actually worth? Tell me in the comments — and tell me which coin you are still holding because of it.

Previous

THEY SOLD YOU A 'FIXED SUPPLY' — A COUNTING ERROR FROM 2015 COULD HAVE PRINTED BILLIONS OF XRP FROM NOTHING

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal