What vulnerability did XRPL Labs report in the XRP Ledger's Batch Amendment?
Confirmed Published 2 min read
Short answer
XRPL Labs Discloses Batch Amendment Vulnerability: the xrpl.org blog lists a February 26, 2026 advisory, “Vulnerability Disclosure Report: XRPL Batch Amendment – Unauthorized Inner Transaction Execution,” by XRPL Labs, describing a flaw in the XRP Ledger’s Batch amendment that allowed unauthorized execution of inner transactions. It was published as an advisory on the xrpl.org blog on February 26, 2026. XRPL.org said the amendment had not been activated on mainnet and no funds were at risk.
The full answer
What did XRPL Labs report?
The XRPL.org blog lists the item under Advisories as “Vulnerability Disclosure Report: XRPL Batch Amendment – Unauthorized Inner Transaction Execution,” by XRPL Labs, dated February 26, 2026 [1]. XRPL Labs reported the vulnerability in the XRPL Batch amendment, described as unauthorized inner transaction execution [1].
The report itself says it contains technical details of a Batch amendment bug reported on February 19, 2026 [2]. Its header lists the affected version as rippled 3.1.0 with the Batch amendment enabled. It says Pranamya Keshkamat and Cantina AI identified a critical logic flaw in the signature-validation logic of the amendment [2].
What is the Batch amendment?
Ripple said in September 2025 that XRPL version 2.5.0, published in June 2025, introduced amendments including Batch Transactions [3]. XRPL.org’s February 26, 2026 disclosure report described a flaw in the signature-validation logic of the Batch amendment that let an attacker execute inner transactions on behalf of arbitrary victim accounts without their private keys.
How did the flaw work?
The report explains the root cause. The XRPL.org advisory said Pranamya Keshkamat and Cantina AI identified a critical logic flaw in the signature-validation logic of the Batch amendment on February 19, 2026, affecting rippled 3.1.0 with Batch enabled. According to the advisory, the bug allowed an attacker to execute inner transactions on behalf of arbitrary victim accounts without their private keys [2]. The advisory said the amendment was in its voting phase and had not been activated on mainnet.
The advisory added that this could enable unauthorized fund transfers and ledger state changes [2].
Was any money lost?
No. XRPL.org said the amendment was in its voting phase and had not been activated on mainnet, and that no funds were at risk [2]. Amendments need validator approval before they take effect, which is covered in how XRP Ledger upgrades get approved.
What was done about it?
Version 3.1.1 of rippled, published February 23, 2026, disabled the Batch and fixBatchInnerSigs amendments because of a severe bug [1]. The advisory says this release marks them as unsupported, which stops them receiving validator votes or being activated on the network [2]. That release came three days before the public report.
What is the case for concern?
The flaw was in code that had already shipped in a released server version, 3.1.0 [2]. An outside party found it, not the pre-release review. The same release line also introduced the Single Asset Vault and Lending Protocol, according to the XRPL.org release notes of January 28, 2026 [1]. For the status of lending see whether native lending is live. For earlier incidents on the ledger see the history of halts, forks and losses.
What is not yet known?
As of October 7, 2026, the XRPL.org advisory and release notes give no date for Batch returning to validator voting.
What we know
- xrpl.org stated: “Read More Advisories February 26, 2026 Vulnerability Disclosure Report: XRPL Batch Amendment – Unauthorized Inner Transaction Execution By XRPL Labs Read More Release Notes February 23, 2026 Introducing XRP Ledger version 3.1.1 and Upcoming Devnet Reset Version 3.1.1 of rippled, the reference server implementation of the XRP Ledger protocol, is now available.” [1]
- XRPL Labs reported a vulnerability disclosure on February 26, 2026 concerning the XRPL Batch amendment, described as unauthorized inner transaction execution, published as an advisory on the xrpl.org blog (XRPL.org blog, February 26, 2026).
- The report says the bug was reported on February 19, 2026, and affected rippled 3.1.0 with the Batch amendment enabled (XRPL.org advisory, February 26, 2026).
- XRPL.org said the amendment was in its voting phase, had not been activated on mainnet, and that no funds were at risk (XRPL.org advisory, February 26, 2026).
- Version 3.1.1, published February 23, 2026, disabled the Batch and fixBatchInnerSigs amendments because of a severe bug (XRPL.org blog, February 23, 2026).
What we reason Analysis
- The sequence suggests the amendment process worked as a safety gate here. The advisory says Batch was still in voting, and the 3.1.1 release note says the amendments were disabled before activation. This rests on the XRPL.org advisory and release notes.
- The flaw sat in code that shipped in a released server version, 3.1.0. That is the strongest critique: pre-activation review did not catch it, and an outside finder did. This rests on the XRPL.org advisory naming the finders.
What's still open
- As of October 7, 2026, the XRPL.org advisory and release notes give no date for Batch returning to validator voting.
In plain English
Batch is a proposed XRP Ledger upgrade that lets several transactions be bundled together. A flaw in how it checked signatures could have let an attacker act on someone else’s account. The flaw was found before the upgrade went live, XRPL.org said no funds were at risk, and the software was changed so the upgrade could not be switched on.
Sources
- XRPL Blog (advisory listing and version 3.1.1 release notes) — XRPL.org, 2026-02-26 Primary
- Vulnerability Disclosure Report: XRPL Batch Amendment – Unauthorized Inner Transaction Execution — XRPL.org (by XRPL Labs), 2026-02-26 Primary
- The Next Phase of Institutional DeFi on XRPL — Ripple, 2025-09-22 Company-reported
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
