Ripple moves to shrink XRP Ledger attack surface as AI audit tests lending push
Ripple is shifting to shrink the XRP Ledger’s (XRPL) attack surface as it prepares to broaden native lending.
The firm has really helpful eradicating greater than 10,000 strains of unused XChainBridge code whereas Lending Protocol V1.1 undergoes an AI-only safety evaluation by Sherlock’s Audit Engine.
The parallel efforts come as crypto platforms face renewed strain to strengthen their defenses. More than $1.31 billion was misplaced throughout 344 safety incidents within the first half of 2026, with code vulnerabilities remaining the {industry}’s commonest attack class.
Axelar leaves Ripple with 10,000 strains it now not needs
The authentic case for holding XChainBridge (XLS-38) weakened after Ripple turned to Axelar for the XRPL EVM Sidechain and broader demand for the native bridge failed to materialize.
XLS-38 was designed to let property transfer between XRPL and linked sidechains by witness servers that observe transactions and attest to exercise throughout networks. The structure was supposed to help personal, permissioned, and experimental sidechains, whereas additionally offering a bridge between XRPL mainnet and the EVM Sidechain.
Ripple finally selected Axelar for the EVM Sidechain after evaluating safety, person expertise, decentralization, and the operational calls for of sustaining a bridge.
The firm stated the XLS-38 witness mannequin carried trade-offs that turned more durable to handle as the worth protected by a bridge elevated. Expanding the witness set may enhance decentralization however add coordination and governance complexity, whereas a smaller group would focus extra belief amongst operators.
Ripple introduced its determination to use Axelar in June 2024 however saved XLS-38 accessible for a validator vote and gave builders roughly 12 to 15 months to display demand for personal sidechains that particularly required the modification.
However, that demand failed to attain the extent Ripple anticipated.
The result’s a considerable block of inactive code that builders should proceed sustaining and reviewing although its principal use case has been dealt with elsewhere.
Ripple estimates that withdrawing XChainBridge and the associated fixXChainRewardRounding modification would ultimately take away greater than 10,000 strains from xrpld.
Ripple recognized upkeep burden, contributor complexity, and attack surface as prices of retaining dormant performance, arguing that XRPL ought to stay lean as the community evolves.
The advice doesn’t take away XLS-38 instantly. Ripple controls one validator vote, and the proposal stays topic to the XRPL modification course of.
If the neighborhood helps the change, Ripple plans to first mark XChainBridge as out of date. Validators adopting a software program model containing that designation would cease voting for the modification, permitting the code to be eliminated in a later launch as soon as the community converges.
Ripple additionally left open the potential for reconsidering if builders can display concrete initiatives that also require XLS-38.
Lending raises a special safety problem
Reducing legacy code comes as XRPL prepares to introduce lending infrastructure with considerably more financial interactions to secure.
Lending Protocol V1.1 builds on Ripple’s push to carry native borrowing and lending capabilities to XRPL alongside Single Asset Vaults. The underlying structure combines mortgage lifecycle administration, interest-rate calculations, multi-party payment routing, credential-based permissions, and interactions with asset swimming pools.
Ripple has described the lending system as one of the crucial financially complicated additions developed for XRPL because the community launched.
On Aug. 27, Sherlock said that V1.1 had entered an intensive AI-only security evaluation by its Audit Engine. The system combines a number of AI auditors and frontier fashions with specialised safety capabilities, adjusting protection and depth to the protocol being examined.
Sherlock has not disclosed any findings or a completion date. It stated a fuller account would comply with as soon as the method is completed.
The evaluation follows an unusually in depth safety course of for the sooner lending and Single Asset Vault codebase, the place repeated testing discovered vulnerabilities even after earlier rounds of scrutiny.
Ripple and Immunefi ran a $200,000 attackathon in late 2025 overlaying 35,498 strains of code. It drew 455 submissions from 131 researchers and finally produced 94 distinctive legitimate findings, together with 15 categorised as important and 19 as high severity. Ripple stated it addressed all recognized points.
The firm subsequently subjected the lending system to extra audits, neighborhood testing, fuzzing, and an AI-assisted red-team program.
Between March and May, Ripple’s AI pink workforce filed 20 lending-specific tickets and recognized seven confirmed bugs that have been mounted.
Among them have been an inverted invariant that might have allowed phantom collateral to go undetected, a fee-free spam vector involving mortgage funds, and an integer-overflow challenge that might have brought on a node impasse.
Those findings present a sensible purpose for repeated testing as Ripple works on V1.1. The firm stated the enhancement incorporates associate suggestions and classes from the sooner implementation.
Ripple’s broader AI red-team program has additionally uncovered high-severity points exterior lending. A security-focused xrpld launch earlier this 12 months included fixes for public-facing crash paths, bounds-checking issues and cross-feature interactions recognized by this system and related testing.
Crypto’s attack wave raises the price of missed bugs
The growth of XRPL’s safety program coincides with an industry-wide attack atmosphere that has remained expensive regardless of years of audits and bug-bounty packages.
In July, CertiK recorded $1.315 billion in losses throughout 344 safety incidents in the course of the first six months of 2026.
While that was decrease than the headline determine from a 12 months earlier, H1 2025 included the distinctive $1.45 billion Bybit breach. Excluding that occasion, CertiK calculated that comparable losses rose about 28% this 12 months.
Code vulnerabilities have been essentially the most frequent attack kind, showing in 204 incidents. CertiK additionally discovered that attackers have been more and more returning to contracts greater than a 12 months outdated, displaying how vulnerabilities can stay exploitable properly after software program has been deployed.
Some of the most important losses got here from different weaknesses. Wallet compromises generated greater than $444 million in losses, whereas the Kelp DAO RPC compromise and Drift Protocol breach collectively accounted for $576 million.
That distinction is critical as a result of no code audit, AI-driven or in any other case, addresses each safety menace going through a protocol or its customers.
Ripple has consequently been utilizing a number of layers of testing fairly than relying completely on AI. Its lending improvement course of has included impartial audits, public safety competitions, fuzzing, formal strategies, neighborhood testing and AI-assisted vulnerability discovery.
Ripple’s personal safety researchers have additionally cautioned in opposition to treating AI as a alternative for skilled evaluation. The firm stated its AI pipelines produce false positives and that human validation stays significantly vital for refined bugs the place a mannequin can misread how an invariant is meant to behave.
That creates a further check for Sherlock’s AI-only engagement. The evaluation may present how far specialised fashions can prolong protocol-security protection, however its usefulness will finally rely on the vulnerabilities it identifies and whether or not these findings translate into fixes earlier than V1.1 advances.
For now, Sherlock has launched no outcomes. Ripple is subsequently making an attempt to cut back recognized sources of pointless complexity in a single a part of XRPL whereas subjecting the subsequent technology of monetary performance to more and more aggressive scrutiny earlier than extra worth depends upon it.
The submit Ripple moves to shrink XRP Ledger attack surface as AI audit tests lending push appeared first on CryptoSlate.
