XRP Ledger version 3.3.0 officially launched on August 6, 2026, bringing the results of a six-month bug bounty program with Web3 security firm Sherlock. Through this inaugural contest worth a total of $550,000 RLUSD, dozens of security researchers dismantled the network’s layer-1 code and found 96 valid vulnerabilities: 59 low-risk, 29 medium, six high, and two classified as critical.
The two critical findings carried the exact same threat: hackers could drain XRP wallet balances without ever holding the original owner’s private keys.
The first bug nested in the Batch Transactions feature, which was designed to execute up to eight operations simultaneously in a single package. Independent security researcher Pranamya Keshkamat and Cantina’s AI tool Apex discovered this on February 19, 2026. They identified a loophole in the validation of external transaction signatures that featured an early exit shortcut. If exploited, an attacker could empty the victim’s balance down to the minimum reserve limit in a single run, including taking over account settings and deleting data without authorization.
The second threat was equally fatal. This loophole was hidden in the Permission Delegation feature and allowed an attacker to take other people’s XRP by exploiting a technical error fee system.
Why No Funds Were Lost
Although the threat could have crippled the network, not a single cent of user funds was lost. When the Batch Transactions code was audited, the feature was still held below the 80% validator approval threshold. This means that although the weapon was in the code, the trigger was not yet active on the mainnet.
The developers’ response also cut off any attack opportunities. Just four days after the first discovery, Ripple released an emergency update version 3.1.1 on February 23, 2026, which changed the status of the feature to unsupported. Now, a full fixed version named BatchV1_1 has been shipped with release 3.3.0, removing the code shortcut and tightening the authorization system.
Ripple paid out a total of $309,000 RLUSD directly to the researchers, while the remaining prize pool was used for Sherlock’s operational costs. Over six months, this audit dissected five new areas, including decentralized exchange integration features, confidential transfers, and sponsored fees.
Against the Patchwork Tradition
This contest marks a rare step in the crypto industry. The firm Sherlock usually only audits smart contracts based on the Solidity language. Dissecting the C++ code stack on foundational infrastructure like the XRP Ledger is a rarely touched territory.
However, the most striking difference is in the timing of the response. The crypto industry is too accustomed to patching code vulnerabilities only after user funds have already been stolen. Ripple’s choice to pay hackers hundreds of thousands of dollars to inspect the building’s structure before its doors are fully opened shows that there is a cheaper way than paying for post-hack losses.
Reported from crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




