Avalanche Founder Warns AI Could Expose Hidden Bugs In XRP Ledger Avalanche founder Emin Gün Sirer warned on October 9 that advanced AI tools will find system-level vulnerabilities in major blockchains such as XRP Ledger long before cryptography like ECDSA is broken, writing "We will see AI exploiting system-level bugs long before ECDSA goes away." His warning followed XRPL developers' September 25 emergency release of xrpld version 3.4.1, which patched "security-sensitive issues" without shipping source code and bundled the fixBatchV1_2 amendment that was set to activate on October 9, with unupgraded node operators risking an "amendment blocked" state. Multiple outlets including Decrypt reported the flaw was flagged by an AI-powered bug-hunting system rather than a human auditor, and Ripple has since added adversarial code scanning, AI-assisted review on every pull request, threat modeling and automated edge-case simulation, with its next XRPL release prioritizing bug fixes over new features. Emin Gün Sirer says the real threat to blockchains like XRP Ledger isn't a cryptographic breakthrough, it's AI finding the software bugs humans missed. XRPL just patched one of those bugs days before he said it. Here's the warning in plain terms: on October 9, Avalanche founder Emin Gün Sirer argued that advanced AI tools are getting close to finding system-level vulnerabilities in major blockchains, XRP Ledger included, long before anyone cracks the underlying cryptography. "We will see AI exploiting system-level bugs long before ECDSA goes away," he wrote, pointing to the elliptic-curve signature scheme that secures most of crypto as the wrong thing to worry about right now. His timing wasn't random. Just two weeks earlier, on September 25, XRPL developers pushed out an emergency release, xrpld version 3.4.1, to patch what they called "security-sensitive issues." The fix shipped without its source code, an unusual move for an open-source project, and came bundled with a new network amendment called fixBatchV1 2. According to a report from CoinAlertNews, that amendment was on track to activate on October 9, the same day Sirer posted his warning, and any node operator who hadn't upgraded by then risked getting stuck off the network entirely, a state XRPL calls "amendment blocked." The bug itself traces back to Batch, a feature that lets XRPL bundle several transactions so they all succeed or all fail together. The ledger's original Batch implementation was scrapped after developers found a critical flaw in it. BatchV1 1 was supposed to be the clean replacement. The September patch suggests it wasn't entirely clean either. What makes this more than a hypothetical is how the vulnerability reportedly surfaced in the first place. Multiple outlets, including Decrypt, reported that the XRPL Foundation moved to patch the flaw after it was flagged by an AI-powered bug-hunting system, not a human auditor combing through the codebase line by line. No exploitation was observed before the fix went out. That's the good outcome. It's also exactly the scenario Sirer is pointing at: a machine finding something a team of engineers had already reviewed and missed. XRP Ledger agentic payments race toward 10 million as AI agents pay each other directly https://startupfortune.com/xrp-ledger-agentic-payments-race-toward-10-million-as-ai-agents-pay-each-other-directly/ Agent-to-agent payments on the XRP Ledger have surged past 3.99 million transactions through the x402 protocol, with RippleX projecting the network will blast through 10 million soon. The milestone is a live test of the agentic commerce model crypto and payments giants are racing to build. - how XRP Ledger handles payments between AI agents https://startupfortune.com/xrp-ledger-agentic-payments-race-toward-10-million-as-ai-agents-pay-each-other-directly/ - AI agents paying each other directly on blockchain https://startupfortune.com/xrp-ledger-agentic-payments-race-toward-10-million-as-ai-agents-pay-each-other-directly/ Ripple didn't shrug this off. The company is now folding AI directly into how XRPL gets built, according to reporting from Decrypt and MEXC: adversarial code scanning, AI-assisted review on every pull request, threat modeling for how new features interact with old ones, and automated simulation of edge cases that are tedious to construct by hand. Ripple has also said its next XRPL release will prioritize bug fixes over new features, a notable reprioritization for a chain that's spent the past two years adding capabilities like Batch and tokenized asset support. Frankly, that response tells you Ripple takes the risk seriously, not that the risk is gone. Sirer didn't name a specific unpatched flaw in XRPL, and he offered no evidence of an actual AI-driven attack happening anywhere in crypto today. His argument is about trajectory, not an active exploit. But the September patch gives his warning a concrete anchor it would otherwise lack: a real bug, in a real feature, caught days before validators were set to adopt it network-wide. XRP's price dipped to a two-week low around the same stretch, according to Decrypt's reporting, though plenty was happening in crypto markets that week beyond one founder's blog post. XRP remains a top-10 token by market capitalization, held across retail wallets and, increasingly, institutional balance sheets betting on Ripple's cross-border payment rails. That scale is exactly why a credible security critique from a rival chain's founder doesn't stay confined to a technical mailing list. Sirer's broader point lands on a debate that's been running through crypto all year, one that usually centers on Vitalik Buterin and Charles Hoskinson sparring over whether quantum computing will someday break Bitcoin and Ethereum's signature schemes. Sirer is saying that conversation is pointed at the wrong decade. The nearer danger isn't a quantum computer breaking ECDSA. It's a language model reading rippled's codebase faster and more thoroughly than any human team ever has, and finding the next Batch-style bug before the patch notes are even written. Also read: FinCEN withdraws its crypto mixing and unhosted wallet rules three years later https://startupfortune.com/fincen-withdraws-its-crypto-mixing-and-unhosted-wallet-rules-three-years-later/ • Trump-linked stablecoin USD1 adds $427 million in a single week https://startupfortune.com/trump-linked-stablecoin-usd1-adds-427-million-in-a-single-week/ • Polkadot launched its own stablecoin and traders dumped DOT anyway https://startupfortune.com/polkadot-launched-its-own-stablecoin-and-traders-dumped-dot-anyway/ This article is posted in Crypto News https://startupfortune.com/category/crypto/ , check it out for more related stories. Ethereum Researcher Urges Crypto Bunker Mode as AI Threatens Wallet Keys https://startupfortune.com/ethereum-researcher-urges-crypto-bunker-mode-as-ai-threatens-wallet-keys/ Justin Drake's warning lands as CoinDesk reports more than 6 million bitcoin, nearly a third of the supply, already sit behind exposed public keys vulnerable if AI cracks ECDSA's underlying math. - ethereum wallet security against AI threats https://startupfortune.com/ethereum-researcher-urges-crypto-bunker-mode-as-ai-threatens-wallet-keys/ - how to protect crypto keys from artificial intelligence https://startupfortune.com/ethereum-researcher-urges-crypto-bunker-mode-as-ai-threatens-wallet-keys/ Join the discussion Open in the community → https://startupfortune.com/community/ Almost there. Sign in and your reply posts straight away.