cryptonews
2026-08-05 14:18:00

RippleX Is Bringing Back Two Features That Had Critical Security Flaws: Will Validators Trust Rewrite?

In the latest XRP news, RippleX expects to ship xrpld 3.3.0 the week of August 1, 2026, packaging five amendments for validator consideration, including rewritten versions of Batch and Permission Delegation, both of which were blocked before mainnet activation after security researchers discovered separate critical authorization flaws in their original implementations. No funds were ever lost. The question now is whether the ecosystem extends enough trust for the rewrites to clear the 80% validator threshold. Xrp (XRP) 24h 7d 30d 1y All time Discover: Everyone’s Got a Take. Get Free $25 to Actually Trade Yours XRP News: What Broke the First Time, and How The original Batch amendment contained a signature-validation bug that allowed an attacker to execute inner transactions from arbitrary victim accounts without ever holding their private keys. According to the official XRPL vulnerability disclosure , researcher Pranamya Keshkamat and Cantina AI’s autonomous audit tool Apex identified the flaw on February 19, 2026, while the amendment was still in its voting phase. UNL validators were advised to vote against it the same evening; an emergency release, rippled 3.1.1, marked both Batch and the related fixBatchInnerSigs amendment as unsupported to prevent any activation path. XRPL has already proven it can support tokenized assets at scale. Now it’s time to put these assets to use: global transfers, trading, collateralizing, and settling. The upcoming release of xrpld 3.3.0 includes five amendments that move XRPL significantly closer to that goal.… — Jazzi Cooper (@jazzicoop) July 31, 2026 The root cause was a loop-exit error in the signer-validation logic: when the code encountered a new account whose signing key matched its own, it declared success and exited without checking the remaining signers, meaning a forged signer entry for any victim account would never be inspected. The exploit path let an attacker drain a victim account down to its reserve through unauthorized Payment transactions. The replacement, BatchV1_1, redesigns that authorization logic and is now flagged in the 3.3 development registry as supported with a default No vote pending validator approval. Permission Delegation exposed a different attack surface. A September 2025 disclosure documented how an invalid offline-signed transaction could still charge the delegated account a transaction fee before failing authorization, because the code checked permissions before verifying the signature, and tec-type errors carry a fee charge by design. A malicious actor could repeatedly submit such transactions with elevated fees to silently bleed a victim account’s XRP balance. The fix reclassifies the relevant error from tec to ter and reorders checks so no fee can be deducted before signature verification. The replacement, PermissionDelegationV1_1, carries the same default No designation in the 3.3.0 registry. This pattern of catching bugs before mainnet is consistent with the broader XRPL security maintenance cadence , which has seen multiple hotfix releases address protocol-level issues ahead of activation. Discover: Your Market Calls Are Worth Something. Start With Free $25 on Kalshi Three New Amendments Target Institutional Tokenization The remaining three amendments are new additions aimed at the institutional tokenization market. Confidential MPT uses elliptic-curve cryptography and zero-knowledge proofs for Multi-Purpose Token balances and transfer amounts, keeping them opaque on the public ledger while remaining auditable by designated entities, such as regulators. It addresses the most consistent objection from financial institutions evaluating public blockchain infrastructure: that counterparty exposure is visible to everyone. The feature targets tokenized government bonds, real estate, equities, and private credit, asset classes where confidentiality is a baseline operational requirement, not a preference. The broader XRPL push into this space is already underway, with active infrastructure development for capital markets tokenization on the XRP Ledger . $XRP is heading into another important software week as xrpld 3.3.0 gets ready for release. The update is expected between August 3 and August 9 and will put five proposed changes in front of validators. One would let up to eight transactions complete together as a single… — MRCΛULIMΛN (@mrcauliman) August 3, 2026 Sponsored Fees and Reserves allow a bank, issuer, or platform to cover transaction fees and reserve requirements on behalf of its users, removing the requirement for end users to hold XRP before transacting. This substantially lowers onboarding friction for institutional deployments, though it also reopens the structural debate: if end-users no longer need XRP to interact with the ledger, demand dynamics shift toward institutional settlement volume rather than retail token utility. That outcome is neither confirmed nor refuted until the amendment activates and institutions actually deploy it. Dynamic MPT closes the third gap, allowing token issuers to modify specified properties, fees, metadata, and predefined parameters after issuance without migrating to a new token entirely. Photo: Jazzi Cooper Jazzi Cooper, RippleX’s head of product, announced the five amendments on X, describing XRPL as having already demonstrated its capacity to support tokenized assets at scale and framing the new features as the infrastructure layer for global transfers, trading, collateralization, and settlement. Cooper confirmed that all five require validator voting before activation. Discover: Get Paid to Be Right, $25 to Start on Kalshi Don’t Miss Out on Our $1,000 USDT Airdrop on ByBit The post RippleX Is Bringing Back Two Features That Had Critical Security Flaws: Will Validators Trust Rewrite? appeared first on Cryptonews .

가장 많이 읽은 뉴스

관련뉴스

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.