Close Menu
xpertsstudio

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Coinbase to Halt Trading for BADGER and STORJ on Sept. 28

    August 28, 2026

    XRP Price Prediction August 29: Important Levels After 5% Crash | News

    August 28, 2026

    Should CASHCAT traders expect a major price correction in the near term?

    August 28, 2026
    Facebook Instagram YouTube WhatsApp TikTok Telegram
    xpertsstudio
    Facebook Instagram YouTube WhatsApp TikTok Telegram
    • Home
    • DeFi News
    • Altcoin News
    • Bitcoin News
    • Ethereum News
    • Crypto Business
    • Crypto Markets
    • Crypto Regulation
    • More
      • Blockchain & Web3
    xpertsstudio
    Home»Altcoin News»Ripple moves to shrink XRP Ledger attack surface as AI audit tests lending push
    August 28, 20260 Views

    Ripple moves to shrink XRP Ledger attack surface as AI audit tests lending push

    EditorBy EditorAugust 28, 2026No Comments6 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Follow Us
    Google News Flipboard
    Ripple moves to shrink XRP Ledger attack surface as AI audit tests lending push
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Don't want to trade it yourself?

    Our desk runs DEX portfolios on profit share.

    35% Share
    $2.5K Minimum
    Learn more
    1. Ripple wants to remove more than 10,000 lines of unused XChainBridge code while Lending Protocol V1.1 undergoes an AI-only Sherlock security review.
    2. The push comes after earlier XRPL lending reviews uncovered 94 valid issues, including 15 critical and 19 high-severity findings.
    3. Sherlock has yet to disclose results, leaving the effectiveness of the AI-only review and the fate of XLS-38 unresolved.

    Ripple is moving to shrink the XRP Ledger’s (XRPL) attack surface as it prepares to expand native lending.

    The company has recommended removing more than 10,000 lines of unused XChainBridge code while Lending Protocol V1.1 undergoes an AI-only security review through Sherlock’s Audit Engine.

    The parallel efforts come as crypto platforms face renewed pressure to strengthen their defenses. More than $1.31 billion was lost across 344 security incidents in the first half of 2026, with code vulnerabilities remaining the industry’s most common attack category.

    Axelar leaves Ripple with 10,000 lines it no longer wants

    The original case for keeping XChainBridge (XLS-38) weakened after Ripple turned to Axelar for the XRPL EVM Sidechain and broader demand for the native bridge failed to materialize.

    XLS-38 was designed to let assets move between XRPL and connected sidechains through witness servers that observe transactions and attest to activity across networks. The architecture was intended to support private, permissioned, and experimental sidechains, while also providing a bridge between XRPL mainnet and the EVM Sidechain.

    Ripple ultimately chose Axelar for the EVM Sidechain after evaluating security, user experience, decentralization, and the operational demands of maintaining a bridge.

    The company said the XLS-38 witness model carried trade-offs that became harder to manage as the value protected by a bridge increased. Expanding the witness set could improve decentralization but add coordination and governance complexity, while a smaller group would concentrate more trust among operators.

    Ripple announced its decision to use Axelar in June 2024 but kept XLS-38 available for a validator vote and gave developers roughly 12 to 15 months to demonstrate demand for private sidechains that specifically required the amendment.

    However, that demand failed to reach the level Ripple expected.

    The result is a substantial block of inactive code that developers must continue maintaining and reviewing even though its principal use case has been handled elsewhere.

    Ripple estimates that withdrawing XChainBridge and the related fixXChainRewardRounding amendment would eventually remove more than 10,000 lines from xrpld.

    Ripple identified maintenance burden, contributor complexity, and attack surface as costs of retaining dormant functionality, arguing that XRPL should remain lean as the network evolves.

    The recommendation does not remove XLS-38 immediately. Ripple controls one validator vote, and the proposal remains subject to the XRPL amendment process.

    If the community supports the change, Ripple plans to first mark XChainBridge as obsolete. Validators adopting a software version containing that designation would stop voting for the amendment, allowing the code to be removed in a later release once the network converges.

    Ripple also left open the possibility of reconsidering if developers can demonstrate concrete projects that still require XLS-38.

    Lending raises a different security challenge

    Reducing legacy code comes as XRPL prepares to introduce lending infrastructure with considerably more financial interactions to secure.

    Lending Protocol V1.1 builds on Ripple’s push to bring native borrowing and lending capabilities to XRPL alongside Single Asset Vaults. The underlying architecture combines loan lifecycle management, interest-rate calculations, multi-party fee routing, credential-based permissions, and interactions with asset pools.

    Ripple has described the lending system as one of the most financially complex additions developed for XRPL since the network launched.

    On Aug. 27, Sherlock said that V1.1 had entered an intensive AI-only security review through its Audit Engine. The system combines multiple AI auditors and frontier models with specialized security capabilities, adjusting coverage and depth to the protocol being examined.

    Sherlock has not disclosed any findings or a completion date. It said a fuller account would follow once the process is finished.

    The review follows an unusually extensive security process for the earlier lending and Single Asset Vault codebase, where repeated testing found vulnerabilities even after previous rounds of scrutiny.

    Ripple and Immunefi ran a $200,000 attackathon in late 2025 covering 35,498 lines of code. It drew 455 submissions from 131 researchers and ultimately produced 94 unique valid findings, including 15 classified as critical and 19 as high severity. Ripple said it addressed all identified issues.

    The company subsequently subjected the lending system to additional audits, community testing, fuzzing, and an AI-assisted red-team program.

    Between March and May, Ripple’s AI red team filed 20 lending-specific tickets and identified seven confirmed bugs that were fixed.

    Among them were an inverted invariant that could have allowed phantom collateral to go undetected, a fee-free spam vector involving loan payments, and an integer-overflow issue that could have caused a node deadlock.

    Those findings provide a practical reason for repeated testing as Ripple works on V1.1. The company said the enhancement incorporates partner feedback and lessons from the earlier implementation.

    Ripple’s broader AI red-team program has also uncovered high-severity issues outside lending. A security-focused xrpld release earlier this year included fixes for public-facing crash paths, bounds-checking problems and cross-feature interactions identified through the program and associated testing.

    Crypto’s attack wave raises the cost of missed bugs

    The expansion of XRPL’s security program coincides with an industry-wide attack environment that has remained costly despite years of audits and bug-bounty programs.

    In July, CertiK recorded $1.315 billion in losses across 344 security incidents during the first six months of 2026.

    While that was lower than the headline figure from a year earlier, H1 2025 included the exceptional $1.45 billion Bybit breach. Excluding that event, CertiK calculated that comparable losses rose about 28% this year.

    Code vulnerabilities were the most frequent attack type, appearing in 204 incidents. CertiK also found that attackers were increasingly returning to contracts more than a year old, showing how vulnerabilities can remain exploitable well after software has been deployed.

    Some of the largest losses came from other weaknesses. Wallet compromises generated more than $444 million in losses, while the Kelp DAO RPC compromise and Drift Protocol breach together accounted for $576 million.

    That distinction is significant because no code audit, AI-driven or otherwise, addresses every security threat facing a protocol or its users.

    Ripple has consequently been using several layers of testing rather than relying exclusively on AI. Its lending development process has included independent audits, public security competitions, fuzzing, formal methods, community testing and AI-assisted vulnerability discovery.

    Ripple’s own security researchers have also cautioned against treating AI as a replacement for expert review. The company said its AI pipelines produce false positives and that human validation remains particularly important for subtle bugs where a model can misinterpret how an invariant is supposed to behave.

    That creates an additional test for Sherlock’s AI-only engagement. The review could show how far specialized models can extend protocol-security coverage, but its usefulness will ultimately depend on the vulnerabilities it identifies and whether those findings translate into fixes before V1.1 advances.

    For now, Sherlock has released no results. Ripple is therefore trying to reduce knownting the next generation of financial functionality to increasingly aggressive scrutiny before more value depends on it

    Related CompanyRippleFinancial technology and enterprise blockchain company
    FeaturedDeFiHacksXRPAI

    Editorial credits

    Source: cryptoslate.com

    Partner offer

    Start trading on Bybit

    Deep derivatives liquidity, tight spreads, and a deposit bonus on your first funding.

    Claim bonus
    attack Ledger Moves Ripple Shrink
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    K
    Mentioned in this article

    KuCoin

    Spot, futures and trading bots in one account. Our link applies a fee discount at signup.

    Open account

    Related Posts

    Should CASHCAT traders expect a major price correction in the near term?

    August 28, 2026

    Goldman Sachs Emerges as Top Institutional Holder of Spot Solana ETFs, 13F Filings Show

    August 28, 2026

    Ethereum Moves Account Abstraction Forward in Hegotá Upgrade

    August 28, 2026
    Leave A Reply Cancel Reply

    Accepting new clients

    Portfolio Management

    Managed trading on centralised and decentralised markets, handled by our experienced trading desk.

    Professional crypto trading management
    Profit share 35%
    Min. capital $2,500
    Wallet Set up by us
    Execution Full service
    How the service works
    • New to on-chain trading? Our team runs it for you on a profit-sharing basis.
    • We create the wallet and place every trade — no DEX experience needed on your side.
    • The share is 35% of profit on each token traded.
    • Minimum starting capital is $2,500.
    Start DEX Management
    Profit share 00%
    Min. capital $0,000
    Custody Your account
    Execution Full service
    How the service works
    • Your funds remain in your own exchange account while our team manages the trading activity.
    • You maintain control of your account and funds throughout the management period.
    • We provide professional trading management based on the agreed strategy and terms.
    • Works with KuCoin, MEXC, Bybit and Phemex.
    • Receive a monthly report covering positions, trading activity and performance.
    CEX management terms, profit split and minimum capital are agreed in writing before onboarding.
    Apply for CEX Management

    Not financial advice. Crypto trading involves substantial risk and past results do not guarantee future returns. Capital can be lost in full. Full terms are agreed in writing before onboarding.

    Trusted Exchanges

    5

    Open an account through our partner links to claim fee discounts and sign-up bonuses.

    K KuCoin Spot & futures · trading fee discount M MEXC Widest altcoin listings · low maker fees B Blofin Copy trading · no-KYC onboarding Y Bybit Deep derivatives liquidity · deposit bonus P Phemex Contract trading · zero-fee spot plan

    Affiliate disclosure: We may earn a commission when you sign up through these links, at no extra cost to you. Trading carries risk — never invest more than you can afford to lose.

    Top Posts

    XRP Price to $0.18? Analysts Warn of Drop as Brad Garlinghouse Bets on Ripple’s Crypto Winter

    August 19, 20264 Views

    Term Finance Loses $8.5M In Ethereum Governance Attack

    August 23, 20262 Views

    🚀 Best Crypto Exchange Liquidity Provider

    August 18, 20262 Views
    0% Spot fees

    Phemex zero-fee spot plan

    Sign up with our referral code to activate the plan on a new account.

    CODE · E4G2K
    Redeem
    Most Popular

    XRP Price to $0.18? Analysts Warn of Drop as Brad Garlinghouse Bets on Ripple’s Crypto Winter

    August 19, 20264 Views

    Term Finance Loses $8.5M In Ethereum Governance Attack

    August 23, 20262 Views

    🚀 Best Crypto Exchange Liquidity Provider

    August 18, 20262 Views
    Our Picks

    Coinbase to Halt Trading for BADGER and STORJ on Sept. 28

    August 28, 2026

    XRP Price Prediction August 29: Important Levels After 5% Crash | News

    August 28, 2026

    Should CASHCAT traders expect a major price correction in the near term?

    August 28, 2026

    Stay Ahead of Crypto

    Get the latest crypto, blockchain, and Web3 news delivered straight to your inbox.

    Facebook Instagram YouTube WhatsApp TikTok Telegram
    • About Us
    • Contact us
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 Xperts Studio. Develop by Pro

    Type above and press Enter to search. Press Esc to cancel.