AdvertiseFee Deal Desk

Avalanche

Avalanche Founder Emin Gün Sirer Warns AI Could Surface XRP Zero-Day Bugs

Avalanche founder Emin Gün Sirer says AI could exploit unknown zero-day bugs in the XRP Ledger before ECDSA cryptography is ever broken.

Be a creator
October 9, 2026, 09:02 PM UTC4 min read
AI SummaryAI
  • Avalanche founder Emin Gün Sirer warned on October 9 that AI could exploit XRP Ledger zero-day bugs.
  • Sirer wrote that AI will exploit system-level bugs long before ECDSA cryptography fails.
  • XRP Ledger developers shipped an emergency software update on September 25 without initial source code.
  • Vitalik Buterin warned AI-driven mathematical discovery could attack lattice-based cryptography within two years.
gate.com

Sirer's Zero-Day Warning

Avalanche (AVAX) founder Emin Gün Sirer has warned that artificial intelligence may uncover previously unknown software flaws in the XRP Ledger, a warning with immediate relevance to XRP holders. In a post on X published October 9, Sirer wrote that “we will see AI exploiting system-level bugs long before ECDSA goes away,” a reference to the Elliptic Curve Digital Signature Algorithm, the signing method that currently secures the vast majority of crypto transactions. His claim is that more capable AI models will detect vulnerabilities in blockchain software, supporting libraries and crypto wallets that no human reviewer has ever seen, and that attackers armed with such findings could steal billions long before any mathematical breakthrough undermines the cryptography itself. The targets he listed span the full stack: the ledger's own code, the libraries that applications depend on, and the wallets where users keep their keys. In his framing, the industry has mispriced the threat, directing attention toward speculative proof-breaking mathematics while the audit surface that already exists sits comparatively unexamined; he described attacks on blockchain software as the more current concern, ahead of the fall of existing cryptographic systems.

Sirer sharpened the argument in a remark aimed squarely at Ripple. Anyone who believes the code of a high-value, lightly used chain carries no zero-day bugs, defined as flaws unknown to developers until they are exploited, that are “hard for humans to see but easy for AI to detect” is, in his words, “a deluded person.” He did not name any specific unpatched XRP Ledger vulnerability, and he demonstrated no AI-assisted attack on the network. The XRP price did not feature in his argument, which was framed entirely as a software-security assessment rather than a market call.

September 25 Emergency Patch in the Background

The warning arrives while XRP Ledger security is already under a microscope. Developers behind the ledger rolled out an emergency software update on September 25, and the fixes were shipped initially without their source code. The team has committed to publishing the code together with a technical retrospective, but that disclosure had not appeared as of Sirer's post, which leaves outside auditors unable to review what was patched or why. Until the retrospective lands, the scope of the September incident rests on the maintainers' own description, a gap that has kept the security discussion running for two weeks. His remarks land, in effect, as a challenge to the assumption that lower-profile chains attract enough expert scrutiny to close their own gaps; fewer eyes on a codebase, the argument goes, widens the window in which a machine-guided search could find what humans missed.

The post also reopens a personal dispute. Ripple CEO Brad Garlinghouse previously took issue with Sirer after the Avalanche (AVAX) founder derided Ripple's reported lack of traction with banks, a feud we followed in our coverage of the company's three institutional deals. A separate report recorded an overnight XRP Ledger payments slump at the same time the price held the $1.39 area. The broader debate over AI and cryptography runs through several camps. Ethereum co-founder Vitalik Buterin has warned that AI-driven mathematical discovery could attack assumptions in lattice-based cryptography within two years. Cardano founder Charles Hoskinson dismissed that warning as speculative, arguing the mathematics does not yet support such a timeline. Ethereum researcher Justin Drake has separately flagged AI's potential to one day break ECDSA, the same algorithm Sirer referenced. Sirer concedes the cryptographic risk cannot be dismissed, but he argues the community's first concern should be vulnerabilities that already exist rather than breakthroughs that have not.

A Warning Without a Named Bug

Our reading is that Sirer's post is a process argument, not an exploit report: the record he published names no vulnerability, no affected file and no technique. That distinction matters for holders. A concrete failure mode, such as an exposed ledger recovery key or an unpatched client, is a present danger; an undemonstrated AI capability is not. AI's commercial footprint today runs from the retail AI trading bot to automated code review, none of it demonstrated against the XRP Ledger. Market context stays separate from the security debate: our XRP technical analysis tracked the loss of the 50-day moving average near $1.39, a market story with no bearing on Sirer's claim. The warning covers a class of risk no record yet measures: no bug count, no audit figure, no demonstrated case.

COINOTAG's editorial and research desk.

AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.