Skip to main content

XRPL Handles Permission Delegation After Critical Bug Discovery 🖤🕷️

XRPL just yanked its Permission Delegation amendment after a bug bounty report uncovered a high-risk flaw during testing 🖤. A hardened V1.1 version has now wrapped up security review and QA checks 😈.

XRPL Reworks Permission Delegation Post Bug Discovery 🌑

This whole thing proves delegation at the protocol level demands solid safeguards way past the basic feature itself. Permission Delegation, aka XLS-75, lets one account hand specific powers to another without giving full control over everything lol. RippleX head of engineering J. Ayo Akinyele explained how the original V1.0 got pulled once a vulnerability surfaced via the bug bounty program before hitting mainnet 💀. Instead they rolled out V1.1 to split the old code from the tougher release.

Delegation Testing Goes Wide Across XRPL Surface 🕸️

Researcher Shotes found a high-severity problem with irrevocable delegate permissions where someone could delete and recreate their account while keeping powers with zero way to revoke them 🔮. V1.1 handles more than a single fix tho by addressing edge cases around delegate identity and blocking newer stuff like Vault and Lending ops from accidental delegation 🔥. It also sorts reserve accounting for delegated payments and closes a multi-signing loophole that might skip checks. QA reports from Ramkumar SG on August 26 logged 179 dedicated tests including 112 functional ones and 48 adversarial security checks 💫. XRP Ledger Operations said every finding got fixed in V1.1 and verified by Cantina with no regressions across 5,088 tests. The feature hit dev in May 2025, got marked unsupported in September, renamed in October, and re-supported by June 2026. For users and custody providers the core capability stays the same as V1.1 only tweaks the activation conditions.


Just another echo from the void by iconofsin.eth 💖



Maybe you like what i'm doing here and wanna support me via the ethereum blockchain: iconofsin.eth 💖

Leave a Reply