Ripple Contest Finds 2 Critical Vulnerabilities in XRP Ledger Features
Ripple's audit-before-release model was put to the test in a $550,000 community contest that uncovered two critical vulnerabilities in XRP Ledger features.
The Sherlock contest, which ran from April 13 to April 27, 2026, found 96 valid bugs across five proposed amendments before they reached mainnet. The contest's prize pool was split between the researchers who discovered the issues and Sherlock's operational costs.
The two critical vulnerabilities were in the Batch amendment and Permission Delegation features. In the Batch amendment, a signature-validation flaw could have allowed attackers to execute transactions from any account without holding its private keys. In Permission Delegation, an attacker could silently drain XRP balances through repeated fee charges on invalid delegated transactions.
Ripple paid $309,000 in RLUSD bounties to contributors and released patches for the affected amendments in version 3.3.0 of the XRP Ledger. The findings highlight the importance of security audits before deployment and raise questions about why more projects do not adopt this approach.