ThreatCluster

XRPL Vulnerabilities: Permission Delegation and Batch Amendment Bugs

First seen 2 Aug 2026, 17:17 UTC xrpl.org 81% similarity 69

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities were reported in the XRPL system affecting different amendments. The first, identified on September 15, 2025, involved the Permission Delegation feature, allowing unauthorized transaction fees to drain XRP from victim accounts. This bug was discovered during the voting phase and was not active on the mainnet. The second bug, reported on February 19, 2026, in the Batch amendment, allowed attackers to execute transactions on behalf of victim accounts without their private keys due to a logic flaw. Both vulnerabilities prompted immediate actions from UNL validators to vote against the amendments, preventing their activation on the mainnet. Remediation efforts are underway, with revised amendments planned for future releases. No funds were at risk for the Batch amendment as it was also in the voting phase when the bug was discovered.

Key Points: • The XRPL Permission Delegation bug could drain XRP by charging unauthorized fees. • The Batch amendment bug allowed unauthorized fund transfers without private keys. • Both vulnerabilities were identified before activation on the mainnet, preventing potential exploitation.

ThreatCluster AI How this analysis works

Timeline

2025-09-15
Permission Delegation bug reported
A bug was reported in the XRPL Permission Delegation feature, allowing unauthorized transaction fees to drain XRP from accounts. Immediate action was taken to prevent its activation.
xrpl.org
2026-02-19
Batch amendment bug reported
A critical logic flaw in the Batch amendment was identified, enabling unauthorized transactions on behalf of victim accounts. The amendment was in the voting phase and had not been activated.
xrpl.org
2026-02-19
UNL validators advised to vote 'No'
Following the discovery of the Batch amendment bug, UNL validators were immediately advised to vote against its activation to mitigate risk.
xrpl.org
2026-08-02
Emergency release for rippled 3.1.1
An emergency release was issued to mark both the Batch and fixBatchInnerSigs amendments as unsupported, preventing their activation.
xrpl.org

Community

Browse all →

Tracked Entities in This Story