The XRP Ledger switched on a new permission-delegation protocol on Oct. 8, giving account holders the ability to assign narrowly defined duties to other accounts without exposing their main signing keys.
Permission delegation on the ledger
The upgrade, named PermissionDelegationV1_1, requires support from at least 80% of trusted validators for two consecutive weeks before activation. With 35 validators in the current roster, a minimum of 29 must back the change. Once live, an account owner can designate up to ten helper accounts, each limited to a specific set of actions rather than a monetary ceiling. This design mirrors traditional corporate segregation of duties, where payment and compliance teams operate under distinct authorizations.
Benefits for banks and stablecoin issuers
Financial institutions that process crypto transactions often keep high-privilege keys online, increasing exposure to cyber-risk. By delegating only the necessary permissions, a bank can keep its primary keys offline while allowing a compliance node to approve new clients or a payment node to execute transfers. Stablecoin providers, such as those issuing Ripple’s RLUSD, can similarly isolate regulatory functions from core treasury operations. The ledger reported roughly $3.72 billion in tokenized assets and $539 million in RLUSD holdings during Q2, underscoring the scale of activity that could benefit from finer-grained controls.
Outstanding technical issue and validator voting
Developers have identified a vulnerability with the PaymentBurn permission. In certain scenarios, a helper granted this right could inadvertently create new tokens instead of merely destroying them. Until a dedicated fix is deployed, the network advises users to avoid delegating PaymentBurn. The patch to resolve this issue has so far gathered 27 of the 35 validator votes, falling short of the 29-vote threshold required to start the two-week countdown for activation.
A separate bug concerns how some ledger servers tally validator support during voting periods. Servers that lose track of validators after a routine security-key rotation may report an inflated support level, potentially skewing proposal outcomes. A proposed remedy would have servers reference validators by a permanent identifier rather than transient metrics; this change remains under review.
Why it matters
The permission-delegation feature equips businesses with on-chain tools to enforce internal controls, reducing reliance on offline key management and lowering the attack surface for malicious actors. As stablecoins and tokenized funds become more integrated into regulated finance, especially in the Asia-Pacific region, the ability to compartmentalize duties directly on the ledger could accelerate adoption and improve compliance monitoring. However, the unresolved PaymentBurn flaw highlights the importance of thorough testing before granting granular permissions, reminding participants that security enhancements must keep pace with functional upgrades.




