Mark RadarMARK RADAR
EN
Event File CRYPTO Blockchain Security

AI Tool Uncovers Critical XRP Ledger Flaw, Averting Potential Theft

1 reports · First detected 2026-02-28 · Last active 2026-02-28

The XRP Ledger (XRPL) is a public blockchain supporting payments and tokenized assets. The proposed Batch amendment, which was awaiting a vote, was designed to allow multiple transactions to be executed in batches. A bypass of its signature verification could have allowed attackers to make payments from any account without obtaining its private key, putting assets across the network at risk and underscoring the value of AI-assisted code audits.

On February 19, 2026, Apex, an autonomous tool developed by Cantina AI, discovered the vulnerability. Ripple's engineering team verified it that evening, and validators on the Unique Node List (UNL) were immediately notified to vote against the amendment. Rippled 3.1.1 was released on February 23, disabling Batch and fixBatchInnerSigs. The flaw never reached mainnet and caused $0 in losses, while the replacement proposal, BatchV1_1, remains under review.

All Coverage

1 original reports

The Backstory

The history behind this event
Ripple Deploys AI to Bolster XRP Ledger Security for Institutional Use2026-03-30 · 2 reports · similarity 0.83

Ripple has long promoted the XRP Ledger (XRPL) and has increasingly targeted institutional applications such as stablecoins and real-world asset tokenization. As adoption by financial institutions expands, vulnerabilities in the underlying protocol could put assets and transactions at risk. Integrating AI into the software development lifecycle is intended to strengthen code reviews and defenses before deployment.

Ripple has embedded machine-learning tools into XRPL code reviews, fuzz testing and AI-assisted red-team exercises, identifying multiple protocol vulnerabilities. The company said fixes and security hardening will be concentrated in the next XRPL release. As of the reports’ publication, Ripple had not disclosed an exact release date, the number of vulnerabilities or the amount invested.

XRPLF Patches Critical XRP Ledger Flaw After AI Bug-Hunting Tool Flags It Before Launch2026-02-27 · 1 reports · similarity 0.93

The XRP Ledger, or XRPL, is a public blockchain supporting XRP and on-chain transactions, while the XRP Ledger Foundation, or XRPLF, promotes its technology and ecosystem. The vulnerability affected signature-verification logic in the yet-to-be-activated Batch amendment. It could have allowed attackers to execute transactions on behalf of accounts and steal assets without their private keys. Cantina’s CEO estimated the direct exposure at nearly $80 billion.

Cantina’s Pranamya Keshkamat and its AI bug-hunting tool Apex discovered the flaw through static analysis and reported it on February 19, 2026. The amendment was still undergoing a validator vote and had not been activated on the mainnet, so no funds were lost. XRPLF advised validators to vote against it and released the emergency rippled 3.1.1 update on February 23, preventing the amendment from being activated.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)