XRP Ledger Retries Permission Split Upgrade for October 5

The network aims to activate a security-fixing upgrade on Oct. 5, allowing accounts to delegate specific tasks without surrendering full key control.
Key points
- The upgrade activates on Oct. 5 if at least 28 of 35 validators support it.
- It allows accounts to delegate specific tasks like payments without sharing master keys.
- A previous version failed due to a bug that allowed attackers to drain fees.
The XRP Ledger is set to activate a critical security upgrade on October 5. This move allows businesses to split compliance duties from payment execution securely.
Twenty-nine of thirty-five trusted validators have already backed the change. The system requires at least twenty-eight supporters to maintain the activation schedule.
Delegated authority protects core keys
Accounts can now grant limited powers to other entities. A stablecoin issuer could let a compliance system approve customers while keeping master keys offline.
Operations accounts receive specific permissions to process payments. They cannot change core settings or grant further authority to third parties.
Critical flaw forced previous retry
An earlier version contained a vulnerability that allowed unauthorized fee draining. Attackers could have depleted balances by submitting invalid transactions with high costs.
The system previously checked permissions before verifying signatures. This sequence allowed fees to deduct even when the transaction was invalid.
Repair ensures signature verification first
The new version fixes this logic error in the software. It now verifies signatures before processing any fee-related actions for unauthorized attempts.
CoinDesk reports that this correction prevents the financial loss risk. The update ships in the latest server software version for node operators.






