XRPL Vulnerabilities: Permission Delegation and Batch Amendment Bugs
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two critical vulnerabilities were reported in the XRPL system affecting different amendments. The first, identified on September 15, 2025, involved the Permission Delegation feature, allowing unauthorized transaction fees to drain XRP from victim accounts. This bug was discovered during the voting phase and was not active on the mainnet. The second bug, reported on February 19, 2026, in the Batch amendment, allowed attackers to execute transactions on behalf of victim accounts without their private keys due to a logic flaw. Both vulnerabilities prompted immediate actions from UNL validators to vote against the amendments, preventing their activation on the mainnet. Remediation efforts are underway, with revised amendments planned for future releases. No funds were at risk for the Batch amendment as it was also in the voting phase when the bug was discovered.
Key Points: • The XRPL Permission Delegation bug could drain XRP by charging unauthorized fees. • The Batch amendment bug allowed unauthorized fund transfers without private keys. • Both vulnerabilities were identified before activation on the mainnet, preventing potential exploitation.