XRPL Activates Flaw- Fixed Amendment Amid Client Application Risks
The XRP Ledger (XRPL) has made significant progress in fixing a critical pre-mainnet flaw, but client applications remain at risk. On September 29, validators plan to activate BatchV1_1, which replaces the original flawed amendment with a rewritten authorization path and additional defenses. The new protocol can reject malformed signatures, but it cannot force wallets or explorers to present inner transaction results clearly.
The flaw was discovered in February when researchers found that an attacker could place a valid signer first and then add a forged entry purporting to authorize a victim account. If the amendment had gone live, unchecked victim transactions could have executed without the victim's keys.
XRPL's response came in two stages: blocking the original Batch and fixBatchInnerSigs amendments with version 3.1.1, followed by the release of BatchV1_1 to replace them. The new protocol requires a multi-account batch to contain the exact set of BatchSigners whose authorization is needed for inner transactions.
The activation of BatchV1_1 will be a conditional test of XRPL's validator process and its surrounding software. It will also begin a real-world test of whether servers, signing libraries, wallets, and data infrastructure agree on the new transaction format and its results.