A new XRP Ledger upgrade could go live on Oct. 5, allowing businesses to assign another account limited permissions, such as processing payments or approving customers, without giving it control over the entire account.
The feature, known as PermissionDelegationV1_1, entered a 14-day activation period on Sept. 21 after receiving support from 29 of the network’s 35 trusted validators. According to the live amendment dashboard, it can activate on Oct. 5 at 11:18 UTC if support remains at or above the required 80% throughout the voting period.
The upgrade could strengthen the XRP Ledger’s appeal as decentralized layer-1 infrastructure for institutional payments by allowing stablecoin issuers, custodians and other businesses to separate day-to-day operations from the keys that control their accounts.
Under the system, payment and compliance tools could receive narrowly defined permissions without gaining access to an issuer’s broader assets or account controls.
The approach resembles how traditional banks divide responsibilities across different teams and systems, with payment processing, compliance and other operational functions handled separately.
The amendment requires continued backing from at least 28 validators. If support falls below that threshold, the 14-day activation countdown resets.
PermissionDelegationV1_1 allows an account to assign permissions based on specific functions. For example, a stablecoin issuer could give an internet-connected compliance system the ability to approve customer accounts for holding its token while keeping the master control keys offline.
A separate operations account could be authorized to make payments without being able to alter the master keys or assign permissions to another account. According to XRPL documentation, each delegate can receive up to 10 permissions, which the primary account can modify or revoke later.
This is the second attempt to activate PermissionDelegationV1_1 on the XRP Ledger.
The initial version contained a vulnerability that could have allowed an attacker to force another account to pay transaction fees for transactions it had not legitimately authorized. Repeated transactions with intentionally high fees could potentially have depleted the victim account’s XRP balance.
The software previously checked whether an account was authorized to execute a transaction before validating its signature. Some failed transactions could still incur fees, allowing XRP to be deducted before the system determined that the signature was invalid, according to an XRPL vulnerability report.
A community tester discovered and reported the issue on Sept. 15, 2025, while testing the feature outside the main network. Validators were subsequently advised to reject the amendment, preventing it from ever activating on the XRP Ledger.
The revised implementation is included in xrpld 3.3.0, the server software used to run XRP Ledger nodes. The update changes the transaction-rejection process so unauthorized transactions cannot incur fees before their signatures have been validated.

More Stories
CFTC Warns Prediction Platforms of Manipulation Risks in ‘Mention Markets’
Lummis Says Trump Opposition Helped Derail Crypto Clarity Act
Solana Tests Upgrade That Could Cut Transaction Finality to 150 Milliseconds