An account on the XRP Ledger may soon allow a secondary account to execute transactions or validate customers on its behalf without surrendering the private keys that govern everything else.
This capability, designated as PermissionDelegationV1_1, commenced a two-week activation window on September 21 after securing backing from 29 out of the network’s 35 trusted validators. According to the live amendment dashboard, it could officially launch on October 5 at 11:18 UTC provided that approval stays at or exceeds 80 percent throughout this duration.
By permitting stablecoin issuers, custodians, and alternative enterprises to decouple routine operations from the keys safeguarding their treasuries, the enhancement could render the XRP Ledger increasingly attractive as decentralized layer 1 architecture for institutional settlements. Consequently, compliance and payment frameworks could execute precisely restricted duties without acquiring extensive jurisdiction over an issuer’s holdings.
Traditional financial institutions operate similarly by internally separating payment execution, regulatory compliance, and additional operational responsibilities, assigning distinct functions to separate personnel or systems.
A minimum of 28 validators must maintain their backing for the upgrade. Any decline beneath this threshold will restart the timer.
The improvement enables an account to partition its authorization according to specific tasks. For instance, a stablecoin issuer could grant an internet-linked compliance mechanism the ability to authorize user accounts for holding its token, while preserving full-control keys offline.
Concurrently, a separate operational profile could obtain authorization to process transfers absent the privilege to alter those master keys or delegate powers to third parties. Based on XRPL documentation, each delegate may acquire up to 10 distinct permissions, which the primary holder can subsequently modify or withdraw.
PermissionDelegationV1_1 represents the platform’s secondary attempt at rolling out this functionality.
The initial iteration contained a vulnerability that could have enabled a malicious actor to compel a separate account to cover fees for unverified or improperly signed transactions. Continuous transmissions featuring intentionally inflated fees could have depleted the target’s XRP reserve.
As outlined in an XRPL vulnerability report, the software evaluated whether an account held authorization to execute a transfer prior to authenticating its digital signature. Specific failure types still incurred a fee deduction, meaning funds could be withdrawn prior to the protocol identifying the signature as invalid.
A participant within the testing community identified the security gap on September 15, 2025, during pre-mainnet evaluations of the tool. Validators received recommendations to decline the proposal, preventing its deployment.
Originally published at https://www.coindesk.com/tech/2026/09/23/xrp-ledger-retries-upgrade-that-lets-banks-split-payment-and-compliance-duties.