Cryptoslate XRP Ledger Revives Vulnerable Features Amid Security Concerns
Article Content
- •XRP Ledger's version 3.3.0 will reintroduce two features with past security flaws.
- •The Batch amendment could have allowed unauthorized transactions without private keys.
- •Permission Delegation could drain accounts through repeated transaction fees.
The XRP Ledger is set to release version 3.3.0, reintroducing two previously disabled features, Batch and Permission Delegation, due to security vulnerabilities. These amendments were blocked before activation after researchers discovered flaws that could allow attackers to execute unauthorized transactions. The Batch amendment could have enabled attackers to manipulate transactions without private keys, while Permission Delegation could have drained accounts through transaction fees. RippleX's Jazzi Cooper confirmed that five amendments are proposed for the update, including new features aimed at enhancing privacy and user onboarding. The amendments require 80% support from trusted validators for activation. The current version, 3.2.1, is still in use as of August 1, 2026, with no majority support for the new amendments yet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Cantina AI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…