Finance.Biggo
Ripple's Audit Uncovers 96 Bugs, Two Critical Vulnerabilities in XRP Ledger
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A $550,000 audit contest by Sherlock identified 96 vulnerabilities in the XRP Ledger before any user wallets were affected. The audit, which ran from April 13 to 27, 2026, revealed two critical flaws that could drain user accounts without private keys. These vulnerabilities were part of the XRPL version 3.3.0 release on August 6, 2026, which included five proposed amendments. The first critical flaw involved a signature-validation vulnerability in the Batch Transactions feature, while the second was related to Permission Delegation, allowing unauthorized XRP balance depletion. Ripple responded with an emergency release to address the issues. The audit's findings contrast sharply with the prevalent post-exploit security practices in the crypto industry. Ripple distributed $309,000 in bounties to researchers for their contributions. The audit's success raises questions about the overall security practices within the blockchain ecosystem.
Key Points: • Sherlock's audit found 96 vulnerabilities in XRP Ledger, including two critical flaws. • The vulnerabilities could allow attackers to drain accounts without private keys. • Ripple's proactive audit approach contrasts with the industry's common post-exploit fixes.