Back Finance.Biggo Ripple's $550000 Sherlock Audit Caught 96 Bugs, Including Two That Could Drain ...
A $550,000 adversarial audit contest run by Web3 security firm Sherlock uncovered 96 vulnerabilities in XRP Ledger code before the software reached a single user wallet, including two critical flaws that could have allowed attackers to drain accounts without holding private keys. The findings, tied to the rippled 3.3.0 release shipped on August 6, 2026, highlight a security model that stands in sharp contrast to the patch-after-exploit approach still dominant across much of the crypto industry.
The two-week contest, which opened on April 13, 2026, covered five proposed XRPL amendments: Batch Transactions, Permission Delegation, Multi-Purpose Token (MPT) DEX integration, Confidential Transfers for MPTs, and Fees and Reserves. Sherlock's platform listed the engagement as "XRP Ledger - April 2026 Contest - 550,000 RLUSD," with Ripple paying bounties in its own stablecoin. Of the 96 valid findings, 2 were classified as critical, 6 as high severity, 29 as medium, and 59 as low. Ripple distributed $309,000 in RLUSD to contributing researchers.
The most severe flaw predated the contest itself. On February 19, 2026, security researcher Pranamya Keshkamat and Cantina's autonomous AI audit tool Apex independently identified a signature-validation vulnerability in the original Batch amendment while it was still in its validator voting phase. The flaw stemmed from an early-exit condition in the outer transaction's signature-validation code that could be satisfied without properly verifying who was authorizing the inner transactions. In practice, an attacker could have constructed a Batch transaction containing inner Payment operations targeting a victim account, draining it down to its reserve balance without ever holding that account's private keys. The same logic gap would have permitted unauthorized AccountSet, TrustSet, or AccountDelete operations.
RippleX responded with an emergency release. Rippled version 3.1.1, published on February 23, 2026, four days after discovery, marked both the original Batch amendment and its companion fixBatchInnerSigs as unsupported. No funds were lost because the amendment had not yet cleared the 80% validator threshold required for activation. The replacement, BatchV1_1, shipped in version 3.3.0 with the early-exit condition removed and additional authorization guards added.
The second critical vulnerability operated through a subtler mechanism tied to Permission Delegation. A September 2025 disclosure documented how the original implementation allowed an attacker to silently bleed a victim account's XRP balance without accessing its keys. The exploit relied on a design feature of XRPL transaction processing: a transaction that fails with a "tec"-class error still incurs a fee charge, while errors caught before signature verification do not. Because the original code checked whether a delegate account held the relevant permission before verifying the transaction's signature, an attacker could repeatedly submit invalid offline-signed transactions with elevated fees against a delegated account. Each failed transaction would still deduct the fee from the victim's balance. The fix reclassified the relevant error from tec to ter and reordered the checks so that no fee can be deducted before signature verification passes.
The two flaws surfaced roughly five months apart but both were caught before either amendment reached activation:
Under the XRP Ledger's amendment process, each proposal must sustain more than 80% validator support for two consecutive weeks before going live. This separation between code availability and feature activation is a structural advantage that most smart-contract platforms lack. On Ethereum, a deployed contract is live the moment it hits the blockchain. On XRPL, code can ship, undergo further review during the voting window, and still be blocked if validators lose confidence.
The version 3.3.0 release also retired five legacy amendments, including Clawback, fixDisallowIncomingV1, fixInnerObjTemplate, fixNFTokenReserve, and fixUniversalNumber, removing dead code paths that could otherwise accumulate as latent attack surface over time.
Note: Findings from Sherlock's two-week audit contest covering five proposed XRP Ledger amendments. Ripple distributed $309,000 in RLUSD bounties from a $550,000 prize pool.
The audit results arrive amid a brutal year for DeFi security. Exploits exceeded $840 million across more than 50 incidents in the first five months of 2026, a 70% year-over-year increase. North Korea-linked actors accounted for 76% of global crypto hack losses in the first four months of the year, according to blockchain intelligence firm TRM Labs. Most strikingly, 70% of exploited contracts had been audited but lacked any form of post-deployment monitoring.
Ripple has simultaneously been building an institutional infrastructure stack at an aggressive pace. The $1.25 billion acquisition of Hidden Road, a multi-asset prime broker rebranded as Ripple Prime, gave the company a regulated on-ramp for traditional finance. RLUSD reached a $1.72 billion market capitalization in under a year and moved more than $18 billion in transaction volume during Q1 alone. Goldman Sachs had disclosed a $153.8 million position across four XRP ETFs in its Q4 2025 filing, though the bank fully exited that position by the time its Q1 2026 13F was disclosed in May, even as cumulative XRP ETF inflows have since topped $1.39 billion since the November 2025 launch. Ripple secured a full Electronic Money Institution license from Luxembourg in February, UK Financial Conduct Authority permissions in January, and a MiCA Crypto-Asset Service Provider license on July 6.
Note: Goldman Sachs figures per its Q4 2025 and Q1 2026 13F filings, as reported by crypto.news.
The security milestone comes as tensions within the XRPL developer community have spilled into public view. Gen3, a development group in the XRP Ledger ecosystem, has decided to withdraw from building retail-focused projects on the network. The move prompted a sharp response from Panos Mekras, co-founder of Anodos Finance, who described Gen3 co-founder Shen as "one of the most important builders and contributors in the XRPL ecosystem."
Mekras warned that the ecosystem is "slowly dying" and argued that the problems extend beyond any single project. He reported that more developers are leaving the ecosystem than joining, that liquidity conditions remain inadequate to support robust project growth, and that developer tools and infrastructure require continued investment. He emphasized that consumer-focused applications are essential for onboarding new participants to the XRPL, arguing that infrastructure development alone does not address the need for products that ordinary users can access and use.
Gen3's leadership noted difficulties for startups without existing revenue streams or strong relationships with large organizations. The company found it challenging to sustain a retail-oriented business within the current XRPL environment. Despite the pivot away from new retail products, Shen said the company will continue to operate its dUNL validator and remain involved in XRPL's technical progress.
The real test of the Sherlock audit's thoroughness comes after features go live. Zero critical findings in the first 90 days would validate the pre-release model; any post-activation vulnerability would undermine the entire thesis. Validator voting thresholds for the five 3.3.0 amendments will signal confidence in the rewrites, particularly for BatchV1_1 and PermissionDelegationV1_1. Whether Ripple continues with adversarial audit contests for future amendments or reverts to traditional private audits will indicate how deeply the pre-release model is embedded in the development culture.
Skeptics note that finding 96 bugs before release can be framed as evidence of thorough testing or evidence of sloppy development. Both critical vulnerabilities were in the original implementations, meaning they cleared internal review before external researchers caught them. The February 2026 Batch bug was not identified by Ripple's own team but by an independent researcher and an AI tool. If external auditors are the primary safety net, the internal development process may have quality gaps that will eventually produce a vulnerability that no external reviewer catches in time.
GitHub repository : XRPLF/rippled
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
