BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

XRP Ledger Rebuilds Batch After Critical Security Flaw

RippleX has released a fully rebuilt version of the XRP Ledger's Batch amendment after the original implementation was withdrawn over a critical security vulnerability found earlier this year

AnonymousCryptoCompass newsroom
September 16, 2026
3 min read
NEWS
XRP Ledger Rebuilds Batch After Critical Security Flaw
CryptoCompass editorial visual for altcoins coverage.

RippleX has released a fully rebuilt version of the XRP Ledger's Batch amendment after the original implementation was withdrawn over a critical security vulnerability found earlier this year.

What Went Wrong With the Original Batch Amendment

The original Batch amendment contained a signature-validation bug that allowed an attacker to execute inner transactions from arbitrary victim accounts without ever holding their private keys.Researcher Pranamya Keshkamat and Cantina's AI tool Apex identified it on February 19, 2026.Rippled version 3.1.1, published on February 23, 2026, four days after discovery, marked both the original Batch amendment and its companion fixBatchInnerSigs as unsupported, preventing validators from voting on or activating them.No user funds were put at risk because the affected amendment never activated.

The vulnerability disclosure report published on xrpl.org detailed the mechanics: the signer check in the outer transaction could pass without confirming that the entity submitting the batch actually controlled the accounts referenced in the inner transactions.This meant that the atomicity feature designed to improve user experience could have been weaponized to empty any account on the network in a single transaction.

How RippleX Rebuilt Batch V1.1

RippleX software engineer Mayukha Vadari said the original signature problem was found in February before mainnet deployment. The subsequent work included a root-cause fix, reviews by four senior engineers, a Sherlock security contest, and audits from Halborn and Common Prefix.

The review process did not end with the initial vulnerability. RippleX said another 11 issues were found while the replacement implementation was being examined.The additional findings covered signature handling, authorization checks, and software conditions capable of crashing servers. Common Prefix classified one of the vulnerabilities as critical, and according to RippleX's review, the issue could have allowed an attacker to reuse permission that a user had signed and carry out more transactions than the user originally intended to authorize.

Developers rebuilt the feature following the discovery, with Batch V1.1 later included in xrpld 3.3.0, released on August 6.In practice, Batch V1.1 would allow up to eight transactions to execute as one bundle: either all succeed, or all fail. A token swap between two parties could ensure both transfers are completed together rather than leaving one side exposed.

Batch V1.1 is currently one validator vote short of starting a two-week activation countdown.Once 80% of the 35 trusted validators back Batch V1.1, the amendment enters its 14-day majority period. If support holds, the change activates; if it drops below the threshold before the window closes, the countdown resets.The feature could ensure that token swaps, customer payments, and platform fees are completed together, and RippleX says commercial projects using it are under contract or in development.

Sources:CoinDesk: XRP Ledger Is One Vote Away From Starting Its Next Big Payments UpgradeCrypto.news: XRPL Batch Upgrade Nears Activation After Developers Fix 11 BugsRippleX on DEV.to: Batch V1.1, What Changed and Why It's Ready