to leave a comment.

▲ XRP, Blockchain, Cryptocurrency Security/AI Generated Image
The XRP Ledger, based on XRP, discovered a high-risk permission delegation vulnerability before its mainnet application and subsequently withdrew the existing V1.0.
According to cryptocurrency specialized media Cryptopotato on September 10 (local time), the XRP Ledger's Permission Delegation feature, XLS-75, was designed to allow one account to grant specific operational permissions to another account. J. Ayo Akinyele, Head of Engineering at RippleX, explained that V1.0 was withdrawn before mainnet application after a vulnerability was reported through a bug bounty program. Instead of directly modifying the existing implementation, the development team introduced a separate V1.1 with enhanced security.
The high-risk vulnerability discovered by security researcher Shotes indicated that even if a delegated account was deleted and then recreated, it could retain its existing permissions. The account that granted the permissions had no way to revoke them. V1.1 strengthened the identity processing of delegated accounts and the permission revocation procedures.
The development team also prevented new features like Vault and Lending from being unintentionally delegated. They fixed issues with reserve calculations for delegated payments and blocked multi-signature paths that could bypass permission delegation checks. During the review process, a medium-risk unsigned integer overflow was also found in isDelegable. Researchers assessed that there would be no practical impact if the account granting permissions did not behave inappropriately.
A quality assurance report released by Ramkumar SG on August 26 recorded 179 permission delegation specific tests. These included 112 functional tests, 48 adversarial security tests, and 19 cross-functional tests. Interoperability with Batch, Confidential MPT, transaction queues, and multi-signature was also checked. The XRP Ledger Operations team stated that all findings were corrected in V1.1 and verified by the security firm Cantina. No functional regressions were found in 5,088 additional tests.
Permission delegation was introduced in May 2025 and was removed from support in September of the same year for security corrections. In October of the same year, it was renamed PermissionDelegationV1_1 and supported again in June 2026. Akinyele explained, “V1.1 did not change what XLS-75 can do, but rather changed the conditions under which that functionality is activated.” The XRP Ledger Operations team assessed that the tested code is ready for use in a production environment.
[Article Summary]
-The XRP Ledger withdrew V1.0 after discovering a high-risk vulnerability that prevented permission revocation before mainnet application.
-V1.1 corrected several security issues, including permission revocation, account identity processing, multi-signature bypass, and reserve calculation.
-After 179 permission delegation-specific tests and 5,088 additional tests, the XRP Ledger Operations team assessed that the tested code is ready for operation.
*Disclaimer: This article is for investment reference only, and we are not responsible for any investment losses based on it. The content should be interpreted for informational purposes only.*
Newsletter
Get key news delivered to your email every morning
to leave a comment.