XRP Ledger Fixes Critical Bug in Permission Delegation Feature
The XRP Ledger team has fixed a critical bug in its Permission Delegation feature after it was reported through the bug bounty program. The bug allowed a delegate to delete their account and recreate it with retained permissions, making them unrevocable.
J. Ayo Akinyele, head of engineering at RippleX, explained that the team pulled the original V1.0 implementation instead of patching it in place. This allowed them to introduce V1.1, a hardened release that addresses edge cases and fixes several issues.
The changes in V1.1 include stopping newer capabilities, such as Vault and Lending operations, from being delegated unintentionally. It also tightens revocation behavior and fixes reserve accounting for delegated payments. A medium-severity unsigned integer overflow was found in isDelegable, but researchers said it had no meaningful impact without misbehavior by the delegator.
The team conducted extensive testing across 179 dedicated Permission Delegation tests, including functional, adversarial security, and cross-feature tests. All findings were fixed in V1.1 and verified by the Cantina security firm.