Insights

What Else Is In Ledger 32,570

Ledger 32,570 is the earliest complete state anyone has, and it has been read many times for what it says about money. Read for anything else, it gives up more than expected: a single unit of a token nobody has heard of, written by a transaction that no longer exists and never touched since — plus four other things found while looking for it. Whether the founders hid words in their addresses is a separate question with its own answer, over here.

One unit of MEA

The snapshot holds 53 trustlines. Fifty-two of them are the currencies you would expect from a payment network in 2013 — dollars, bitcoin, a few Canadian dollars, one euro, one yen. The fifty-third is a currency code that appears nowhere else in the ledger, before or since:

Currency
Trustlines
USD
29
a currency
BTC
16
a currency
CAD
5
a currency
EUR
1
a currency
JPY
1
a currency
MEA
1
the only non-currency IOU in the entire ledger

One account issued exactly one unit of MEA to another. The issuer’s side carries a balance of −1 against a limit of 0; the holder’s side carries +1 against a limit of 1. It is the smallest possible position: one unit, one holder, one trustline. Our own token records agree — total supply 1, holders 1.

It has not moved in thirteen years

Every object in the ledger carries a PreviousTxnLgrSeq— the index of the ledger in which it was last written. For this trustline it reads the same number in the 2013 snapshot and in validated state today:

index            908D554AA0D29F660716A3EE65C61DD886B744DDF60DE70E6B16EADB770635DB
PreviousTxnLgrSeq  10066   at ledger 32,570 (1 Jan 2013)
PreviousTxnLgrSeq  10066   today
Balance           −1      then, and −1 now
The transaction that created it cannot be retrieved
Ledger 10,066 falls inside the lost range. Every full-history server on Earth begins at 32,570, so the payment that put one MEA on that line is gone — not deleted from the state, which still carries its effect, but unretrievable as a record. We can see precisely what it did and we cannot see it. It is the same situation as the recovered ledger hashes: an effect with a permanently missing cause.

The obvious explanation would be abandonment — two dead wallets, a forgotten test. That is not what happened. The issuer went on to sign 312 transactions between May 2013 and June 2023; the holder signed 582 between February 2013 and June 2023, including 294 offers. They have transacted with each other ten times. Both accounts are alive today. They stayed active for a decade and never once touched this line.

What nobody did

The same sweep turns up an absence that is easy to miss because there is nothing to see. Across all 136 accounts in the snapshot:

0
Domains set
0
Flags set
0
Regular keys
0
Message keys

Not one account set a Domain, an EmailHash, a MessageKey, a RegularKey or a TransferRate. Every single one carries Flags: 0 — no RequireDestTag, no DisallowXRP, no RequireAuth. The mechanisms existed and the founding cohort used none of them.

That is worth stating plainly because it explains a difficulty that runs through all of this work. The XRP Ledger has a built-in way to prove who owns an address, and at the moment its records begin, nobody had used it. Which is why naming the accounts depends on forum posts, domain files published a decade later, and chain analysis — there was never an on-chain alternative to fall back on.

Objects last touched in the first thirty ledgers

Eight accounts in the snapshot were last written to before ledger 30 — and then never again in the 32,540 ledgers that followed, nor in the thirteen years after that.

Ledger 7 is about as close to the beginning as any surviving evidence reaches. Whatever these accounts were for, their entire on-chain life happened in the first few minutes of the network and left a balance that has sat still ever since.

Who was actually busy

Sequence numbers survive the loss: an account’s sequence at ledger 32,570 is one more than the number of transactions it had sent, so the snapshot preserves an exact activity count for a week nobody can read.

Txs sent
Account
Held at 32,570
61
991,482
the distributor
59
8,189,000,000
Chris Larsen
46
201
the genesis account
16
5,919,999,800
OpenCoin
The busiest account of the lost week held 0.001% of the supply
r3kmLJN5… sent 61 transactions before the records begin — more than any other account, and more than the company account and the genesis account combined. It held 991,482 XRP, a rounding error beside the 80 billion next to it. It is also the account that created the first new account after the horizon (ledger 38,129, 10,000 XRP) and that later sent David Schwartz’s address its million. It behaves like the faucet the early network ran on, and it is the closest thing the lost week has to a protagonist.

The counterweight: 100 of the 136 accounts have balances that are exact whole XRP with no drops missing, and every one of them has Sequence: 1. Three quarters of the founding ledger was funded and then sat perfectly still while a handful of accounts did all the work.

There are no hidden messages, and that is now measured

The XRP Ledger has a field designed to carry arbitrary human text: the Memo. If any of the founding accounts ever attached a note to a transaction, it would be there. So we read every memo on every transaction sent by all 136 accounts, across their entire histories to the present day.

Every single one is identical:

MemoType    “client”
MemoData    “gatehub”
MemoFormat  “text/plain”

That is a wallet stamping its own name on transactions it signs — software, not a person. Across thirteen years there is not one human-written memo in the entire founding set. Put beside the zero Domains and zero flags above, the picture is consistent: the founding cohort left no deliberate text anywhere on the ledger. Anyone hunting for an encoded message is hunting in a field that was never used.

The one cluster that survives scrutiny

Direct payments between founding accounts give 94 edges once the seven hub accounts are removed. Most are one-off. A few go both ways, which is more interesting — two accounts paying each other repeatedly is harder to explain as coincidence than a single transfer:

Pair
Payments
Held at 32,570
rphasxS8… ↔ rsQP8f9f…
10 and 7
10,000 and 10,000 XRP
rhdAw3Li… ↔ rfitr7nL…
5 and 3
10,001 and 9,999 XRP — summing to 20,000
rM1oqKtf… ↔ r9hEDb4x…
8 and 4
9,100 and 10,000 XRP

But the strongest structure in the snapshot is not a pair. Four accounts hold exactly 370 XRP— an odd, unround amount that appears nowhere else — and they were funded within seven ledgers of one another:

Account
Funded at
Today
All four later paid the same address
Every one of the four sent XRP to rnp8kFTTm6KW8wsbgczfmv56kWXghPSWbK, which held 160,000 XRP at the horizon. That account has ten distinct senders in its entire history, so the cluster accounts for 40% of everyone who has ever paid it. Identical unusual balance, funded seven ledgers apart, converging on one destination — that is the shape of one person setting up several wallets, and unlike the address wordplay it is not something chance produces.
A pattern we found and threw away
Three of those four last transacted on the same day, 25 June 2023 — as did both accounts holding the MEA position. Five old accounts going quiet within hours of each other reads like a coordinated shutdown, and it is not one. Every one of those final transactions is an incoming payment of one drop from radio73EpeWXys6ZkkHk55CcwqmhL6UpcU, sent between 23:27 and 23:29. It is dust spam hitting dormant addresses, and the accounts did not do anything at all that day. We are recording it because it was convincing for about ten minutes.

What chasing one address actually looks like

The account last written at ledger 8 — second-oldest object in the snapshot — is rUnFEsHjxqTswbivzL2DNHBb34rhAgZZZK. It attracts identity speculation because of how it reads, which we test separately and at length. What matters here is different: it is a useful worked example of how far the chain will actually carry you once you start pulling on one account.

10,000 XRP
At ledger 32,570
0
Transactions sent then
266
Lifetime transactions
149.56 XRP
Balance today

Exactly 10,000 XRP with not one drop spent, no trustlines at the horizon, then an active decade — 118 payments, 95 offers created, 25 trustlines opened — taking in 219,856 XRP and sending out 1,250. An early hands-on user, in other words, not a founder wallet: founder accounts received round billions and sat still.

A link we found, published, and then had to downgrade
Its history contains a direct payment from the account attributed to Arthur Britto 10,000.000000 XRP on 13 February 2013, ledger 218,527, two parties, no intermediary. We first described that as its only contact with a named founder, which is true and misleading.

Britto’s account sent 121 XRP payments to 76 distinct accounts, and 47 of them were for exactly 10,000 XRP— sometimes three within the same minute. The b34r payment is one of forty-seven. Receiving it places an account in a crowd, not in anyone’s confidence. It is the same error as reading meaning into a payment from a distributor that paid 1,526 accounts, and we made it twice before catching it.

The rest is negative and worth stating precisely, because absence is a result. Chris Larsen’s account appears nowhere in those 266 transactions, in either direction. Nor does David Schwartz’s— across 266 and 1,400 transactions respectively there is no contact at all, and the ten counterparties they share are mass distributors, gateways, and rrrrrrrrrrrrrrrrrrrrBZbvji, the placeholder that appears in pathfinding rather than any real party.

What the account does have is an ordinary relationship with rM1oqKtfh1zgjdAgbFmaRm3btfGBX25xVo— 79 interactions and a mutual BTC trustline, the two of them trading with each other for years. That account is unnamed too. The chain will tell you who someone dealt with; it will not tell you who they were.

Nothing in the client ever mentioned them

Since the software and the ledger were written by the same small group, a founding address embedded in the client — a constant, a seed, even a comment — would be there to find. We checked the source as it stood on 1 January 2013, the day ledger 32,570 closed. It holds twelve address literals in total, and the only founding account among them is the genesis account, which is there because its private key is a published default. None of the other 135 appears anywhere.

That check, the repository it was called at the time, and what the genesis account’s published key means for how that account looks today, are covered in the lost-ledgers article.

Method

State at ledger 32,570 was read with ledger_data (260 objects: 136 AccountRoot, 65 DirectoryNode, 53 RippleState, 4 Offer, 2 LedgerHashes). Current state came from ledger_entry on the trustline’s own index, plus account_lines, account_info and account_tx. All against s1.ripple.com.

The immutability claim is the strongest one here and rests on a single comparison anyone can repeat: request ledger entry 908D554A…0635DB at ledger 32,570 and at validated, and read PreviousTxnLgrSeq in both. If the two numbers match, the object has not been written to in between. They match.