XRPL Fixes Permission Delegation After Critical Bug Found
XRPL has pulled its Permission Delegation modification after a bug bounty report discovered a high-risk flaw throughout testing, with a hardened V1.1 now finishing safety overview and QA checks.
The episode reveals why delegation on the protocol degree wants safeguards that reach past the fundamental characteristic itself.
XRPL Reworks Permission Delegation After Bug Report
Permission Delegation, generally known as XLS-75, permits one account to offer one other account particular powers to behave on its behalf. The permissions are supposed to be slender, slightly than giving the delegate management over all the account.
RippleX head of engineering J. Ayo Akinyele explained that the unique V1.0 implementation was pulled after a vulnerability was reported by the bug bounty program earlier than it reached the XRPL mainnet. Instead of patching that model in place, the group launched V1.1 to separate the unique implementation from the hardened launch.
A researcher referred to as Shotes found a high-severity concern involving irrevocable delegate permissions, the place a delegate might delete their account and later recreate it whereas protecting no matter permissions it had been handed by one other account, with no manner for the unique account to revoke them.
The modifications transcend a single bug. V1.1 addresses edge instances involving delegate identification and stops newer capabilities, together with Vault and Lending operations, from being delegated unintentionally. It additionally fixes reserve accounting for delegated funds and closes a multi-signing route that would bypass delegation checks. Revocation conduct was tightened as effectively.
The overview additionally discovered a medium-severity unsigned integer overflow in isDelegable, which might permit a malformed permission worth to be interpreted as a delegable transaction kind, though researchers stated the difficulty had no significant impression with out misbehavior by the delegator.
Testing Expands Across XRPL’s Delegation Surface
A QA report printed by Ramkumar SG on August 26 recorded 179 devoted Permission Delegation checks, together with 112 purposeful checks, 48 adversarial safety checks, and 19 cross-feature checks. Testing additionally coated interactions with Batch, Confidential MPT, the transaction queue, and multi-signing.
XRP Ledger Operations said that every one findings had been mounted in V1.1 and verified by the Cantina safety agency. Its QA group additionally reported no regressions throughout 5,088 checks and famous there have been no open inner bugs categorized as essential, concluding that the characteristic was prepared for manufacturing use on the examined commit degree.
Permission Delegation was launched in May 2025, marked as unsupported in September 2025 pending a safety repair, renamed PermissionDelegationV1_1 in October, and re-supported in June 2026.
As CryptoPotato reported final week, a public dashboard constructed by developer Denis Angell has been tracking how totally XRPL amendments get exercised on devnet earlier than reaching mainnet, and delegation was among the many amendments it had flagged as incomplete.
For customers and custody suppliers, the supposed functionality remains to be unchanged. As Akinyele put it, V1.1 doesn’t change what XLS-75 can do; as an alternative, it modifications the situations beneath which that functionality is activated.
The put up XRPL Fixes Permission Delegation After Critical Bug Found appeared first on CryptoPotato.
