XRPL Fixes Permission Delegation After Critical Bug Found

1 week ago 17



XRPL also tightened delegation rules to prevent newer Vault and Lending features from being delegated by accident. XRPL has pulled its Permission Delegation amendment after a bug bounty report found a high-risk flaw during testing, with a hardened V1.1 now completing security review and QA checks. The episode shows why delegation at the protocol level needs safeguards that extend beyond the basic feature itself. XRPL Reworks Permission Delegation After Bug Report Permission Delegation, known as XLS-75, allows one account to give another account specific powers to act on its behalf. The permissions are meant to be narrow, rather than giving the delegate control over the entire account. RippleX head of engineering J. Ayo Akinyele explained that the original V1.0 implementation was pulled after a vulnerability was reported through the bug bounty program before it reached the XRPL mainnet. Instead of patching that version in place, the team introduced V1.1 to separate the original implementation from the hardened release. A researcher called Shotes found a high-severity issue involving irrevocable delegate permissions, where a delegate could delete their account and later recreate it w...

Read Entire Article