The post AI tool catches bug that could have drained Ripple-linked token from wallets appeared on BitcoinEthereumNews.com. An autonomous AI security tool caughtThe post AI tool catches bug that could have drained Ripple-linked token from wallets appeared on BitcoinEthereumNews.com. An autonomous AI security tool caught

AI tool catches bug that could have drained Ripple-linked token from wallets

An autonomous AI security tool caught a bug in the XRP Ledger that, if left undetected, could have let an attacker steal funds from any account on the network without ever touching the victim’s private keys.

The vulnerability, disclosed Thursday by XRPL Labs, sat in the signature-validation logic of the Batch amendment, a pending upgrade that would allow multiple transactions to be bundled and executed together.

The amendment was still in its voting phase among validators and had not been activated on mainnet, meaning no funds were ever at risk. But the exploit path was about as bad as it gets for a blockchain.

Here’s what the bug did in plain terms. Batch transactions let users bundle several operations into one. Because the individual transactions inside the batch don’t carry their own signatures, the system relies on a list of batch signers to confirm that every account involved has authorized the bundle.

The validation function that checked those signers had a critical loop error. If it encountered a signer whose account didn’t yet exist on the ledger, and whose signing key matched their own account — the normal case for a brand-new account — it immediately declared the entire check successful and stopped looking at the rest of the list.

An attacker could exploit this by constructing a batch with three transactions. The first creates a new account the attacker controls. The second is a simple transaction from that new account, making it a required signer. The third is a payment from the victim’s account to the attacker.

Because the new account doesn’t exist yet when validation runs, the signer check exits early after the first entry and never verifies the second. The victim’s funds move without their keys ever being involved.

Pranamya Keshkamat and Cantina AI’s autonomous security tool Apex identified the flaw through static analysis of the codebase on Feb. 19 and submitted a responsible disclosure. Ripple’s engineering team validated the report the same evening with an independent proof-of-concept.

The response was fast. Validators on the network’s Unique Node List were immediately advised to vote “No” on the amendment.

An emergency release, rippled 3.1.1, was published on Feb. 23, marking both the Batch and the related fixBatchInnerSigs amendments as unsupported to prevent them from ever activating. A corrected replacement called BatchV1_1 has been built and is under review, with no release date set.

The fact that an AI tool found this is notable on its own.

XRPL Labs said it would add AI-assisted code audit pipelines as a standard step in its review process going forward, alongside expanded static analysis specifically designed to catch the kind of premature loop exits that caused this bug.

Source: https://www.coindesk.com/tech/2026/02/27/ai-tool-catches-critical-xrp-ledger-bug-that-could-have-drained-wallets

Market Opportunity
Everscale Logo
Everscale Price(EVER)
$0.00309
$0.00309$0.00309
+0.98%
USD
Everscale (EVER) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Golden Trump statue holding Bitcoin appears outside U.S. Capitol

Golden Trump statue holding Bitcoin appears outside U.S. Capitol

The post Golden Trump statue holding Bitcoin appears outside U.S. Capitol appeared on BitcoinEthereumNews.com. A 12-foot golden statue of Trump gripping a Bitcoin was placed outside the U.S. Capitol on Wednesday evening in Washington. The installation appeared just before the Federal Reserve’s latest interest rate announcement. It stood along 3rd Street from 9 a.m. to 4 p.m., pulling crowds as D.C. tried to make sense of a foam version of the president staring down Congress with a crypto in hand. At 2 p.m., the Fed cut its benchmark interest rate by 0.25 percentage points, bringing the short-term rate from 4.3% to 4.1%. It’s the first rate cut since December, after a year of concerns about slowing job growth and rising unemployment. The Fed also outlined plans for two more cuts before the end of this year, but said it only expects one cut in 2026. That didn’t sit well with Wall Street, which had priced in five cuts by next year, as Cryptopolitan extensively reported. Crypto organizers livestream token to support Trump statue The statue was funded by a group of cryptocurrency investors, most of whom are staying anonymous. Their goal was to make a loud, unavoidable point about the future of crypto and government power. Hichem Zaghdoudi, who spoke for the group, said: “The installation is designed to ignite conversation about the future of government-issued currency and is a symbol of the intersection between modern politics and financial innovation. As the Federal Reserve shapes economic policy, we hope this statue prompts reflection on cryptocurrency’s growing influence.” To push the message even further, the group launched a memecoin on Pump.fun. They used multiple livestreams to pump the token and tie it directly to the statue stunt. One organizer, speaking during a stream on Tuesday, said the statue was built using “extremely hard foam” to make it easier to move. Posts on their X account…
Share
BitcoinEthereumNews2025/09/18 15:20
US Senator Targets Prediction Markets, Citing War Bets and Insider Risks

US Senator Targets Prediction Markets, Citing War Bets and Insider Risks

US Senator Chris Murphy has announced plans to introduce legislation banning prediction markets he described as “corrupt and destabilizing” platforms. In a February
Share
Coinstats2026/03/01 01:22
RAY Technical Analysis Feb 28

RAY Technical Analysis Feb 28

The post RAY Technical Analysis Feb 28 appeared on BitcoinEthereumNews.com. RAY exhibits a clear downtrend in the altcoin market, dominated by recent swing lows
Share
BitcoinEthereumNews2026/03/01 01:52