XRPL Debuts Hardened Permission Delegation Amid Bug Fix
XRPL has addressed a high-risk flaw in its Permission Delegation feature after a bug bounty report identified an issue that could have allowed a delegate to delete their account and later recreate it while keeping permissions granted by another account.
The vulnerability was reported through the bug bounty program before the V1.0 implementation reached the XRPL mainnet, prompting the team to introduce V1.1 instead of patching the original version in place.
V1.1 addresses edge cases involving delegate identity and stops newer capabilities, including Vault and Lending operations, from being delegated unintentionally. It also fixes reserve accounting for delegated payments and closes a multi-signing route that could bypass delegation checks.