
XRPL Validators Block Silent Exploit That Could Drain Accounts via Fees
XRP Ledger validators rejected two amendments—BatchV1_1 and PermissionDelegationV1_1—that contained a vulnerability allowing attackers to drain user accounts through inflated transaction fees. The supermajority clock for the amendments has stalled without reaching consensus.
Key Takeaways
- 1## The Rejected Amendments XRPL validators chose not to activate BatchV1_1 and PermissionDelegationV1_1, two network amendments that contained a silent exploit capable of draining victim accounts via transaction fee manipulation.
- 2The amendments remained at default-No status, indicating the network failed to achieve the 80% supermajority required for activation.
- 3The two-week supermajority voting clock expired without the amendments reaching threshold.
- 4## How the Exploit Worked The vulnerability would have allowed an attacker to drain funds from targeted accounts without requiring explicit transaction approval from the victim.
- 5Instead of moving XRP directly, the exploit operated through inflated transaction fees, siphoning value through the ledger's fee mechanism.
The Rejected Amendments
XRPL validators chose not to activate BatchV1_1 and PermissionDelegationV1_1, two network amendments that contained a silent exploit capable of draining victim accounts via transaction fee manipulation. The amendments remained at default-No status, indicating the network failed to achieve the 80% supermajority required for activation. The two-week supermajority voting clock expired without the amendments reaching threshold.
How the Exploit Worked
The vulnerability would have allowed an attacker to drain funds from targeted accounts without requiring explicit transaction approval from the victim. Instead of moving XRP directly, the exploit operated through inflated transaction fees, siphoning value through the ledger's fee mechanism. By rejecting these amendments, validators prevented the exploit from ever becoming active on the network.
Validator Consensus Process
XRPL's amendment voting system requires 80% of validators to agree on network changes before they activate. The silent nature of the exploit—meaning it would have functioned without obvious warning signs—made rejection especially critical. With the amendments now default-No and the voting window closed, the network remains protected from the attack vector.
Why It Matters
For Traders
XRPL's rejection of exploitable amendments reduces risk of undetected fund theft, though the incident had limited market price impact.
For Investors
Validator governance successfully caught and blocked a critical vulnerability before activation, validating XRPL's amendment review process.
For Builders
Protocol teams working on XRPL should tighten fee-related code review; this exploit class is now a known attack surface to audit against.





