Finance.Biggo Ripple's Audit Uncovers 96 Bugs, Two Critical Vulnerabilities in XRP Ledger
Article Content
- •Sherlock's audit found 96 vulnerabilities in XRP Ledger, including two critical flaws.
- •The vulnerabilities could allow attackers to drain accounts without private keys.
- •Ripple's proactive audit approach contrasts with the industry's common post-exploit fixes.
A $550,000 audit contest by Sherlock identified 96 vulnerabilities in the XRP Ledger before any user wallets were affected. The audit, which ran from April 13 to 27, 2026, revealed two critical flaws that could drain user accounts without private keys. These vulnerabilities were part of the XRPL version 3.3.0 release on August 6, 2026, which included five proposed amendments. The first critical flaw involved a signature-validation vulnerability in the Batch Transactions feature, while the second was related to Permission Delegation, allowing unauthorized XRP balance depletion. Ripple responded with an emergency release to address the issues. The audit's findings contrast sharply with the prevalent post-exploit security practices in the crypto industry. Ripple distributed $309,000 in bounties to researchers for their contributions. The audit's success raises questions about the overall security practices within the blockchain ecosystem.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…