Skip to content
Project UpdatesLatest

XRP Ledger Launches "Permissioned Delegation" for Banks, Advancing Stablecoin Compliance

MissedBlock Desk · · 4 min read

Updated

XRP Ledger Launches "Permissioned Delegation" for Banks, Advancing Stablecoin Compliance

XRP Ledger Enables Permission Delegation for Institutions, Faces Minor Vulnerabilities

October 8, 2023 – The XRP Ledger (XRPL) has activated its PermissionDelegationV1_1 feature, a significant upgrade designed to allow institutions to delegate specific operational permissions to independent accounts while keeping master keys securely offline. This enhancement aims to provide a decentralized mechanism for banks and stablecoin issuers on-chain, though it comes with a known vulnerability in the PaymentBurn permission that awaits a patch.

On-Chain Decentralization for Institutions

The PermissionDelegationV1_1 feature, enabled on the evening of October 8th, marks a crucial step for the XRP Ledger in its pursuit of institutional compliance. In essence, businesses can now grant certain operational rights to separate “helper accounts.” The keys controlling the primary assets, however, can remain stored in offline vaults.

Consider a stablecoin issuer. Daily operations require personnel to verify customer identities and approve transactions, tasks that must be available online around the clock. However, if the master key controlling the entire wallet resides on the same system, a hacker intrusion could lead to catastrophic losses. The traditional approach involves storing private keys offline and retrieving them for signing when operations are needed, but this proves inefficient for 24/7 financial services.

Permission delegation addresses this challenge by compartmentalizing responsibilities. Account owners can assign up to 10 specific permissions to helper accounts, such as “approve new customers,” “execute payments,” or “freeze specific accounts.” The helper account uses its own key to sign, is restricted to performing only authorized actions, and the owner can modify or revoke these permissions at any time. This mirrors the practice within banks where payment and compliance functions are handled by different departments, but with the rules now embedded at the ledger level, making them immutable.

The Validator Consensus Mechanism

Upgrades to the XRPL are not determined by a single development team but require a vote from “validators.” The XRPL currently has 35 trusted validators, and any upgrade proposal must receive over 80% support for two consecutive weeks, meaning at least 29 votes.

The countdown for PermissionDelegationV1_1 was reset in September when the proposal fell below the support threshold. Following renewed campaigning, it was officially activated on October 8th, according to records from the monitoring platform XRPL Dashboard.

Identified Vulnerabilities

However, this upgrade is not without its imperfections. The official XRPL documentation explicitly warns users against delegating the “PaymentBurn” permission. While originally designed to allow helpers to destroy tokens, under specific conditions, it also permits them to “create” new issued tokens (not XRP itself, but other tokens issued on the XRPL). If an institution inadvertently grants PaymentBurn permission to a helper account, it could lead to unauthorized token inflation.

A fix for this vulnerability is currently underway. On Friday, it received 27 votes of support, falling just two votes short of the 29-vote threshold required to initiate the two-week countdown for activation. Until the patch is deployed, the risk associated with delegating PaymentBurn remains.

The XRPL development team is also investigating another issue related to vote counting. A report submitted on GitHub on October 8th highlighted that some XRPL servers were removing validators from the counting list after they rotated their routine security keys, even though the validator remained online and continued to vote. This would reduce the denominator in support rate calculations (e.g., from 35 to 33), making proposals appear closer to passing than they actually are. A correction, which involves using a permanent ID to identify validators, is in a pull request and is currently under review.

Driving Institutional Adoption

According to data provided to CoinDesk by XRP custodian Evernorth, the XRPL held an average of $3.72 billion in tokenized assets in the second quarter, along with approximately $539 million in Ripple’s RLUSD stablecoin, totaling about $4.26 billion. The managers of these assets are the target users for the permission delegation feature, requiring 24/7 operations without exposing their master keys.

The XRP Ledger launched in 2012, predating Ethereum. For years, Ripple has emphasized the XRPL as a “ledger designed for banks,” but genuine institutional adoption has been slow, partly due to the XRPL’s long-standing lack of enterprise-grade features like granular permission controls. The introduction of permission delegation, coupled with the XRPL’s inherent support for freezing and burning functions, enhances its competitiveness in stablecoin compliance and tokenized fund scenarios.

However, the two pending bug fixes (the PaymentBurn vulnerability and the validator counting issue) underscore the remaining fragilities in the XRPL’s governance and upgrade processes. While upgrades require over two weeks of validator consensus, proposals can also have their voting countdown reset due to a loss of votes from a minority of nodes. Such delays represent a risk that institutional clients, who prioritize certainty, must consider.

XRP Ledger Launches "Permissioned Delegation" for Banks, Advancing Stablecoin Compliance · MissedBlock