XRPL has pulled its Permission Delegation modification after a bug bounty report discovered a high-risk flaw throughout testing, with a hardened V1.1 now finishing safety overview and QA checks.
The episode exhibits why delegation on the protocol degree wants safeguards that stretch past the essential characteristic itself.
XRPL Reworks Permission Delegation After Bug Report
Permission Delegation, generally known as XLS-75, permits one account to offer one other account particular powers to behave on its behalf. The permissions are supposed to be slim, fairly than giving the delegate management over the complete account.
RippleX head of engineering J. Ayo Akinyele defined that the unique V1.0 implementation was pulled after a vulnerability was reported by way of the bug bounty program earlier than it reached the XRPL mainnet. As a substitute of patching that model in place, the staff launched V1.1 to separate the unique implementation from the hardened launch.
A researcher known as Shotes discovered a high-severity situation involving irrevocable delegate permissions, the place a delegate may delete their account and later recreate it whereas maintaining no matter permissions it had been handed by one other account, with no method for the unique account to revoke them.
The adjustments transcend a single bug. V1.1 addresses edge circumstances involving delegate id and stops newer capabilities, together with Vault and Lending operations, from being delegated unintentionally. It additionally fixes reserve accounting for delegated funds and closes a multi-signing route that would bypass delegation checks. Revocation habits was tightened as properly.
The overview additionally discovered a medium-severity unsigned integer overflow in isDelegable, which may enable a malformed permission worth to be interpreted as a delegable transaction sort, though researchers stated the problem had no significant affect with out misbehavior by the delegator.
Testing Expands Throughout XRPL’s Delegation Floor
A QA report printed by Ramkumar SG on August 26 recorded 179 devoted Permission Delegation exams, together with 112 practical exams, 48 adversarial safety exams, and 19 cross-feature exams. Testing additionally coated interactions with Batch, Confidential MPT, the transaction queue, and multi-signing.
XRP Ledger Operations stated that every one findings had been mounted in V1.1 and verified by the Cantina safety agency. Its QA staff additionally reported no regressions throughout 5,088 exams and famous there have been no open inside bugs labeled as crucial, concluding that the characteristic was prepared for manufacturing use on the examined commit degree.
Permission Delegation was launched in Might 2025, marked as unsupported in September 2025 pending a safety repair, renamed PermissionDelegationV1_1 in October, and re-supported in June 2026.
As CryptoPotato reported final week, a public dashboard constructed by developer Denis Angell has been monitoring how totally XRPL amendments get exercised on devnet earlier than reaching mainnet, and delegation was among the many amendments it had flagged as incomplete.
For customers and custody suppliers, the supposed functionality remains to be unchanged. As Akinyele put it, V1.1 doesn’t change what XLS-75 can do; as a substitute, it adjustments the circumstances beneath which that functionality is activated.
The publish XRPL Fixes Permission Delegation After Crucial Bug Discovered appeared first on CryptoPotato.