RippleX Ships xrpld 3.3.0 With Rewritten Batch and Permission Delegation Amendments

RippleX expects to ship xrpld 3.3.0 the week of August 1, 2026, packaging five amendments for validator consideration. The release includes rewritten versions of Batch and Permission Delegation, both previously blocked before mainnet activation after security researchers discovered separate critical authorization flaws in their original implementations. No funds were lost from either vulnerability. The core question is whether the XRPL ecosystem extends sufficient trust for the rewrites to clear the 80% validator approval threshold required for activation.

Batch Amendment Exposed Signature-Validation Exploit

The original Batch amendment contained a signature-validation bug that allowed an attacker to execute inner transactions from arbitrary victim accounts without holding their private keys. According to the official XRPL vulnerability disclosure, researcher Pranamya Keshkamat and Cantina AI's autonomous audit tool Apex identified the flaw on February 19, 2026, while the amendment was still in its voting phase. UNL validators were advised to vote against it the same evening. An emergency release, rippled 3.1.1, marked both Batch and the related fixBatchInnerSigs amendment as unsupported to prevent any activation path.

The root cause was a loop-exit error in the signer-validation logic: when the code encountered a new account whose signing key matched its own, it declared success and exited without checking the remaining signers. This meant a forged signer entry for any victim account would never be inspected. The exploit path let an attacker drain a victim account down to its reserve through unauthorized Payment transactions.

The replacement, BatchV1_1, redesigns that authorization logic and is now flagged in the 3.3 development registry as supported with a default No vote pending validator approval.

Permission Delegation Allowed Unauthorized Fee Charges

Permission Delegation exposed a different attack surface. A September 2025 disclosure documented how an invalid offline-signed transaction could still charge the delegated account a transaction fee before failing authorization. The code checked permissions before verifying the signature, and tec-type errors carry a fee charge by design. A malicious actor could repeatedly submit such transactions with elevated fees to silently bleed a victim account's XRP balance.

The fix reclassifies the relevant error from tec to ter and reorders checks so no fee can be deducted before signature verification. The replacement, PermissionDelegationV1_1, carries the same default No designation in the 3.3.0 registry.

Three New Amendments Target Institutional Tokenization

The remaining three amendments are new additions aimed at the institutional tokenization market.

Confidential MPT uses elliptic-curve cryptography and zero-knowledge proofs for Multi-Purpose Token balances and transfer amounts, keeping them opaque on the public ledger while remaining auditable by designated entities, such as regulators. It addresses the objection from financial institutions that counterparty exposure is visible to everyone on public blockchain infrastructure. The feature targets tokenized government bonds, real estate, equities, and private credit.

Sponsored Fees and Reserves allow a bank, issuer, or platform to cover transaction fees and reserve requirements on behalf of its users, removing the requirement for end users to hold XRP before transacting. This lowers onboarding friction for institutional deployments.

Dynamic MPT allows token issuers to modify specified properties, fees, metadata, and predefined parameters after issuance without migrating to a new token entirely.

All Five Amendments Require Validator Voting

Jazzi Cooper, RippleX's head of product, announced the five amendments on X, describing XRPL as having already demonstrated its capacity to support tokenized assets at scale and framing the new features as the infrastructure layer for global transfers, trading, collateralization, and settlement. Cooper confirmed that all five require validator voting before activation.

FAQ

What security flaws were discovered in the original Batch and Permission Delegation amendments?

The original Batch amendment contained a signature-validation bug that allowed attackers to execute inner transactions from victim accounts without holding their private keys. Researcher Pranamya Keshkamat and Cantina AI's Apex identified the flaw on February 19, 2026. Permission Delegation allowed invalid offline-signed transactions to charge delegated accounts transaction fees before failing authorization, as documented in a September 2025 disclosure. Both amendments were blocked before mainnet activation, and no funds were lost.

When will RippleX ship xrpld 3.3.0 with the rewritten amendments?

RippleX expects to ship xrpld 3.3.0 the week of August 1, 2026. The release packages five amendments for validator consideration, including BatchV1_1 and PermissionDelegationV1_1, which are rewritten versions of the previously blocked amendments. All five amendments require validator voting and must clear the 80% validator approval threshold before activation.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments