Following a two-week validator approval process, the XRP Ledger activated its PermissionDelegationV1_1 upgrade on October 8. This change introduces fresh operational controls for businesses handling digital assets by letting account holders assign specific tasks to other accounts without compromising their primary security keys. At the same time, developers cautioned the community about a distinct permission flaw that might enable unauthorized token generation under specific circumstances.
According to XRPL Dashboard, the feature went live late Thursday once the network fulfilled its voting criteria. This amendment lets account owners bestow restricted authority while keeping complete oversight of their funds and account settings.
This rollout arrives after a setback in September when validator backing dipped below the necessary percentage, prompting a reset of the amendment’s activation countdown as CoinDesk previously reported.
XRP Ledger Secures Validator Approval for Upgrade
The XRP Ledger mandates over 80% backing from trusted validators sustained across 14 consecutive days to implement any amendment. Out of the 35 validators currently on the trusted roster, a minimum of 29 must endorse a proposed modification.
During its latest tracked approval window, PermissionDelegationV1_1 garnered 30 votes. This renewed majority took effect around 21:25 UTC on September 24, establishing October 8 as the earliest possible activation date.
The network processes these amendment choices through specialized flag ledgers that emerge roughly every 16.5 minutes, meaning that meeting the approval deadline does not instantly trigger feature activation.
The upgrade provides a mechanism to split account duties cleanly without revealing primary signing keys. Each authorized account is eligible to hold up to 10 distinct permissions for particular operations. While these controls limit what a secondary account is allowed to do, they do not automatically enforce spending caps.
Read More: XRP, XLM Outlook: Derivatives Data Signals Caution as Price Momentum Weakens
Firms frequently need continuous access to signing keys for day-to-day transactions. Storing powerful keys on web-connected systems elevates potential vulnerabilities if attackers breach those environments.
By utilizing delegation, companies can offload routine tasks to separate accounts while storing their main keys offline. Each designated account relies on its own keys while functioning strictly within the boundaries set by the owner.
As an illustration, a stablecoin issuer might grant a compliance account the authority to clear customers without providing broader administrative access over the whole account. The primary holder retains the ability to alter or cancel these permissions at any time.
Traditional financial institutions already divide payment processing and compliance duties among different personnel. This XRPL update brings comparable functional divisions straight to blockchain account privileges.
Developers Address Token Risk and Validator Voting Bug
Despite the successful launch, official XRPL guidelines caution participants against delegating the PaymentBurn privilege until a separate patch is deployed. The PaymentBurn feature is designed to allow an authorized account to destroy issued tokens, but under specific conditions, the existing framework could additionally allow that same account to mint new tokens.
This vulnerability impacts native assets issued on the XRP Ledger rather than the creation of new XRP. All other granular permissions remain safe from this warning. On Friday, the proposed patch for PaymentBurn had collected 27 out of 35 votes from trusted validators, requiring two additional votes to hit the 29-vote threshold and kick off its mandatory two-week approval cycle.
In a separate development, an October 8 report identified an issue regarding how specific XRPL servers track validator votes. Certain servers might stop counting validators following routine security-key updates, even if those validators remain fully operational.
For example, losing visibility on two validators would drop a server’s tally from 35 down to 33, potentially skewing its perception of overall amendment support.
Developers have proposed the adoption of permanent validator identifiers to resolve this bug, and the patch remains under evaluation.
These protocol updates unfold as institutional volume scales up across the network. Figures provided by Evernorth to CoinDesk show that during the second quarter, the XRPL averaged USD 3.72 billion in tokenized assets alongside USD 539 million in RLUSD.
Combined, those tracked balances approached approximately USD 4.26 billion, highlighting the rising administrative demands facing the network.
Final Thoughts
The activation of the XRP Ledger’s PermissionDelegationV1_1 brings fresh account controls following the conclusion of its validator approval cycle. Businesses are now equipped to delegate limited operational duties without risking their main keys. Meanwhile, developers continue working to resolve the PaymentBurn permission risk and the separate validator-counting glitch, with both remedies still moving through the pipeline.




