How XRPL validators quietly killed a silent exploit that could have drained victim accounts through transaction fees alone
RippleX expects xrpld 3.3.0 soon, bringing rewritten Batch and Permission Delegation amendments back into XRP Ledger validator software after earlier versions were blocked over security flaws. The release is still prerelease, and validator approval is still required before any activation. Five features are proposed for 3.3.0: Confidential MPT, Batch, Permission Delegation, Sponsored Fees and Reserves, and Dynamic MPT. Batch’s original version had an authorization flaw that could have let attackers run inner transactions for arbitrary accounts without private keys. Permission Delegation had a different flaw: invalid offline-signed transactions could still charge transaction fees, potentially draining XRP through repeated submissions. Neither amendment activated on mainnet, and no funds were lost. The 3.3 development registry now marks the rewritten BatchV1_1 and PermissionDelegationV1_1 as supported with default No votes, meaning the code understands them but activation still depends on validator supermajority. No mainnet majority countdown is active yet. If activated, all servers would need compatible software or risk becoming amendment blocked.
