XRP Ledger Upgrade Returns With Focus on Separating Bank Payment and Compliance Roles
The XRP Ledger could activate a new permissioning feature on Oct. 5 that would allow businesses to assign specific account functions to other accounts without giving them full control over the underlying wallet.
PermissionDelegationV1_1 entered its 14-day activation period on Sept. 21, following support from 29 of the network’s 35 trusted validators. The amendment is expected to activate at 11:18 UTC on Oct. 5 if at least 80% of validators continue to support it, based on the live amendment dashboard.
The feature is designed to help institutions separate operational tasks from access to an account’s primary control keys. Stablecoin issuers, custodians and other businesses could authorize separate systems to perform limited functions while keeping their main credentials protected.
A stablecoin issuer could, for example, give an internet-connected compliance system permission to approve customers for its token while keeping the keys with full account authority offline. Another delegated account could be allowed to send payments without receiving the ability to modify the main account or grant permissions to additional users.
Each delegate can receive up to 10 permissions under the XRPL design, while the primary account retains the ability to change or remove those permissions.
The approach could help businesses divide payment, compliance and other operational responsibilities across separate systems, similar to established controls used by traditional financial institutions.
The amendment needs continued backing from at least 28 validators to complete activation. If support drops below that threshold, the 14-day countdown will restart.
This is the second attempt to introduce the PermissionDelegation feature. The original version was withdrawn after a security issue was discovered involving transaction fees.
The earlier implementation could potentially allow an attacker to make another account pay fees for transactions that had not been properly authorized. Repeated submissions carrying high fees could have drained XRP from the affected account.
An XRPL vulnerability report found that the previous software checked transaction permissions before verifying the signature. As a result, certain failed transactions could incur fees before the system detected that the signature was invalid.
A community tester reported the vulnerability on Sept. 15, 2025, while testing the amendment outside the mainnet. Validators were subsequently advised to reject it, and the original version never went live.
The replacement is included in xrpld 3.3.0, the server software used to run XRP Ledger nodes. Its revised validation sequence prevents unauthorized transactions from being charged fees before their signatures have been verified.
Share this content:













