TLDR AI tool Apex and a researcher found a flaw in XRPL Batch amendment Bug allowed unauthorized transactions without victim private keys Amendment was not activeTLDR AI tool Apex and a researcher found a flaw in XRPL Batch amendment Bug allowed unauthorized transactions without victim private keys Amendment was not active

XRPL Blocks Critical Batch Amendment Bug Before Reaching Mainnet Launch

2026/02/27 16:33
4 min read

TLDR

  • AI tool Apex and a researcher found a flaw in XRPL Batch amendment
  • Bug allowed unauthorized transactions without victim private keys
  • Amendment was not active on mainnet and no funds were lost
  • Rippled 3.1.1 blocks Batch and fixBatchInnerSigs activation

The XRPL Foundation has patched a critical flaw in the Batch amendment before it reached mainnet activation. The issue was detected during the voting phase and was blocked through an emergency software update.

The vulnerability was identified on Feb. 19, 2026, by security engineer Pranamya Keshkamat and Cantina AI’s autonomous tool Apex. The foundation confirmed that no user funds were at risk because the amendment had not been activated.

Vulnerability Found Before Mainnet Activation

The flaw existed in the signature validation logic of the proposed Batch amendment, also known as XLS-56. The amendment would allow multiple inner transactions to be grouped into a single batch. These inner transactions were designed to remain unsigned. Authorization would instead rely on the outer batch’s list of signers.

According to the XRPL Foundation, a loop error in the signer validation function caused the issue. When the system encountered a signer for an account not yet created, it could exit early. If the signing key matched the new account, validation was marked successful. The system then skipped checks for the remaining signers.

This behavior created a path for unauthorized transactions. An attacker could execute transactions from victim accounts without private keys. The amendment was still under validator voting at the time of discovery. It had not been enabled on the XRPL mainnet. The foundation stated, “The amendment was in its voting phase and had not been activated on mainnet; no funds were at risk.”

How the Exploit Could Have Worked

The reported exploit required a carefully structured batch transaction. An attacker would include three inner transactions within a single batch. One transaction would create a new account controlled by the attacker. Another would submit a simple transaction from that new account. The third would attempt a payment from a victim account to the attacker. The attacker would provide two batch signer entries. 

One signer entry would be valid for the newly created account. The second would falsely claim to authorize the victim account. Due to the early loop exit, the system could accept the first signer and skip validation of the second. The victim’s payment could then execute without authorization.

The XRPL Foundation stated that such an exploit could have allowed fund transfers and ledger changes. It also noted the risk of ecosystem disruption if widely abused. Cantina and Spearbit CEO Hari Mulackal said, “Our autonomous bug hunter, Apex, found this critical bug.” Ripple engineering teams reproduced the issue with a proof of concept. A full unit test was also completed before remediation began.

Emergency Patch and Ongoing Review

Following disclosure, UNL validators were advised to vote “No” on the Batch amendment. An emergency software release, rippled 3.1.1, was published on Feb. 23, 2026. This version marks both Batch and fixBatchInnerSigs as unsupported. As a result, they cannot receive validator votes or activate on the network.

The update does not include the final logic correction. It acts as an immediate safeguard to block activation. A corrected replacement called BatchV1_1 has been implemented. The updated version removes the early exit and strengthens authorization checks. The amendment is under review, and no release date has been set. 

Additional safeguards are also planned. The foundation plans to expand AI-assisted code audits. It will also extend static analysis to detect premature success returns in loops. The XRPL Foundation confirmed it has patched the critical flaw before mainnet activation. The early intervention prevented unauthorized transactions and protected network integrity.

The post XRPL Blocks Critical Batch Amendment Bug Before Reaching Mainnet Launch appeared first on CoinCentral.

Market Opportunity
Ucan fix life in1day Logo
Ucan fix life in1day Price(1)
$0.0006503
$0.0006503$0.0006503
-13.25%
USD
Ucan fix life in1day (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

“We Cannot in Good Conscience Agree”: Anthropic Defies Pentagon Over AI Weapons

“We Cannot in Good Conscience Agree”: Anthropic Defies Pentagon Over AI Weapons

TLDR The Pentagon is demanding Anthropic remove safety guardrails from its Claude AI so it can be used for any lawful purpose, including autonomous weapons and
Share
Coincentral2026/02/27 20:18
Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future

Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future

TLDR Wormhole reinvents W Tokenomics with Reserve, yield, and unlock upgrades. W Tokenomics: 4% yield, bi-weekly unlocks, and a sustainable Reserve Wormhole shifts to long-term value with treasury, yield, and smoother unlocks. Stakers earn 4% base yield as Wormhole optimizes unlocks for stability. Wormhole’s new Tokenomics align growth, yield, and stability for W holders. Wormhole [...] The post Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future appeared first on CoinCentral.
Share
Coincentral2025/09/18 02:07
Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse?

Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse?

Whales offload 200 million XRP leaving market uncertainty behind. XRP faces potential collapse as whales drive major price shifts. Is XRP’s future in danger after massive sell-off by whales? XRP’s price has been under intense pressure recently as whales reportedly offloaded a staggering 200 million XRP over the past two weeks. This massive sell-off has raised alarms across the cryptocurrency community, as many wonder if the market is on the brink of collapse or just undergoing a temporary correction. According to crypto analyst Ali (@ali_charts), this surge in whale activity correlates directly with the price fluctuations seen in the past few weeks. XRP experienced a sharp spike in late July and early August, but the price quickly reversed as whales began to sell their holdings in large quantities. The increased volume during this period highlights the intensity of the sell-off, leaving many traders to question the future of XRP’s value. Whales have offloaded around 200 million $XRP in the last two weeks! pic.twitter.com/MiSQPpDwZM — Ali (@ali_charts) September 17, 2025 Also Read: Shiba Inu’s Price Is at a Tipping Point: Will It Break or Crash Soon? Can XRP Recover or Is a Bigger Decline Ahead? As the market absorbs the effects of the whale offload, technical indicators suggest that XRP may be facing a period of consolidation. The Relative Strength Index (RSI), currently sitting at 53.05, signals a neutral market stance, indicating that XRP could move in either direction. This leaves traders uncertain whether the XRP will break above its current resistance levels or continue to fall as more whales sell off their holdings. Source: Tradingview Additionally, the Bollinger Bands, suggest that XRP is nearing the upper limits of its range. This often points to a potential slowdown or pullback in price, further raising concerns about the future direction of the XRP. With the price currently around $3.02, many are questioning whether XRP can regain its footing or if it will continue to decline. The Aftermath of Whale Activity: Is XRP’s Future in Danger? Despite the large sell-off, XRP is not yet showing signs of total collapse. However, the market remains fragile, and the price is likely to remain volatile in the coming days. With whales continuing to influence price movements, many investors are watching closely to see if this trend will reverse or intensify. The coming weeks will be critical for determining whether XRP can stabilize or face further declines. The combination of whale offloading and technical indicators suggest that XRP’s price is at a crossroads. Traders and investors alike are waiting for clear signals to determine if the XRP will bounce back or continue its downward trajectory. Also Read: Metaplanet’s Bold Move: $15M U.S. Subsidiary to Supercharge Bitcoin Strategy The post Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse? appeared first on 36Crypto.
Share
Coinstats2025/09/17 23:42