QuiverCrypto QUIVERCRYPTO SUBSCRIBE
QuiverCrypto
← Blog

Ripple enhances XRP Ledger security while preparing for lending expansion

Ripple is tightening security on the XRP Ledger by removing unused code as it readies for expanded lending functionality.

28 September 2026 · 6 min read
Ripple enhances XRP Ledger security while preparing for lending expansion

Ripple is currently taking significant steps to enhance the security of the XRP Ledger (XRPL) as it gears up to expand its lending capabilities. The company has put forward a plan to eliminate over 10,000 lines of unused XChainBridge code while its new Lending Protocol V1.1 undergoes a thorough AI-driven security audit through Sherlock’s Audit Engine. This dual approach comes as the cryptocurrency sector faces increasing scrutiny and urgency regarding platform security.

In the first half of 2026, losses from security incidents across the crypto landscape soared to over $1.31 billion, with vulnerabilities in code cited as the most common point of attack. The urgency behind Ripple’s security initiatives reflects the broader context of a challenging environment for crypto platforms.

XChainBridge's unsustainable presence

The push to remove dormant code is largely fueled by Ripple's decision to opt for Axelar as its bridge solution for the XRPL EVM Sidechain. The initial premise for maintaining XChainBridge (XLS-38) came into question when demand for this native bridging solution failed to materialize. Originally designed to facilitate the movement of assets between the XRPL and connected sidechains efficiently, XLS-38 relied on a network of witness servers to confirm transaction validity. However, the architecture proved less viable over time, especially as security requirements evolved.

After a thorough evaluation that included considerations of security, user experience, and operational management for maintaining such a bridge, Ripple concluded that utilizing Axelar’s offering would better serve the community.
Ripple’s assessment indicated that the witness model inherent in XLS-38 presented significant challenges. An expanded witness set could improve decentralization, yet it would also complicate governance and long-term management. Conversely, limiting the witness pool would concentrate trust among a smaller number of operators, a situation that Ripple deemed unacceptable as security needs increased.

In June 2024, after announcing the partnership with Axelar, Ripple allowed the XLS-38 to remain open for a validator vote. It invited developers a 12 to 15-month window to demonstrate any real demand for private sidechains necessitating this specific amendment. Unfortunately, expected interest did not materialize. The result was a reserve of unnecessary dormant code that further burdens developers who must supervise and maintain it even though its original use case is already addressed effectively.

Ripple anticipates that the withdrawal of XChainBridge and the necessary code amendments would save ample maintenance resources, reduce contributor complexity, and minimize security vulnerabilities associated with retaining outdated functionalities. The proposal currently remains under consideration, pending community support.

The evolution of lending infrastructure

As Ripple navigates the removal of obsolete code, it simultaneously aims to implement Lending Protocol V1.1—a structured approach to integrate advanced borrowing and lending functionalities into the XRPL. This initiative is complemented by the introduction of Single Asset Vaults that would greatly increase engagement with financial transactions on the platform.

Ripple’s lending architecture seeks to streamline the entire loan lifecycle. This includes mechanisms for rate calculations, fee distribution among multiple stakeholders, permissions based on credentials, and effective interaction with asset pools, positioning the Lending Protocol as one of the most intricate financial features introduced to XRPL since its inception.

Beginning August 27, Sherlock began an AI-centric security audit for Lending Protocol V1.1 via its innovative Audit Engine, which integrates various AI models to maximize security assessments. However, no results or timelines for this assessment have been disclosed as of yet. A comprehensive report is expected after the review is completed.

Addressing past vulnerabilities

The urgency of security checks is underscored by past experiences in which Ripple previously encountered vulnerabilities during its initial iterations of lending protocols and the Single Asset Vault code. In previous tests, critical vulnerabilities were found even after thorough checks. Notably, a 2025 attackathon organized by Ripple and Immunefi, offering a $200,000 bounty, revealed 94 significant findings out of 455 submissions from 131 different researchers. Among these, 15 were classified as critical architectural flaws.

Leading into the current security checks, the AI red team submitted 20 vulnerability tickets related to the lending system, identifying seven confirmed bugs that have since been rectified. Noteworthy issues tackled include potential exploits for phantom collateral detection, spam vectors in loan transactions, and integer overflow problems that could threaten node stability.

Through proactive testing measures, Ripple aims to leverage feedback from various partners and lessons learned from the earlier lending efforts to fortify the platform going forward. The broader context of increased security threats has compelled Ripple to adopt a comprehensive security strategy that goes beyond relying solely on AI. Their diverse testing regimen includes independent audits, public competitions to identify flaws, and collaborative community efforts to ensure a robust defense.

The larger landscape of security in crypto

As Ripple strengthens its security attempts, it operates within an industry landscape that remains increasingly prone to cyberattacks. Reports from CertiK indicate that $1.315 billion was lost through 344 separate security incidents in the first half of 2026, demonstrating a context where vulnerabilities can lead to significant monetary losses. Even though this mark is lower than preceding years, the uptick from prior incidents emphasizes ongoing flaws within the ecosystem.

Code vulnerabilities emerged as the main vector for attacks, appearing in over 204 cases. Many attackers have shown a proclivity for targeting older contracts, which underscores how vulnerabilities can remain exploitable long after deployment. Losses attributed to wallet compromises and other breaches circle around $576 million—a reflective estimate of the serious security challenges crypto platforms continuously navigate.

As Ripple gears up for integrating enhanced lending capabilities, it has embraced a layered approach to security instead of placing reliance on AI alone. The company has issued warnings against interpreting AI as a replacement for human scrutiny, citing instances where AI pipelines have yielded false positives. The user experience of complex blockchain systems often requires nuanced interpretation that only human review can solidify.

The upcoming AI-driven review by Sherlock represents a remarkable test case for the balance between machine-led oversight and the essential human element in protocol security. Although Ripple’s proactive approach to managing redundancies in its codebase carries its merits, its ultimate success hinges on the findings from the audit process and how effectively Ripple can react to any vulnerabilities discovered.

As both Ripple and the wider crypto community brace for a future filled with complex financial interactions, the emphasis on robust security frameworks has never been greater. The industry must tackle legacy issues while innovating to address the heightened risks that accompany advancing functionalities.

Oluwapelumi values Bitcoin's potential. He shares insights on a range of topics such as decentralized finance (DeFi), security vulnerabilities, mining, and the sociocultural impact of cryptocurrency, encapsulating the transformative potential of blockchain technology.