How is XRP kept secure if it isn't mined?
Also asked as: “How does XRP Ledger consensus work without mining?” · “Is XRP centralized, and who controls the validators?” · “How many validators does the XRP Ledger have?”
Confirmed Published 6 min read
Short answer
The XRP Ledger is secured by its own consensus protocol, not by mining or staking: servers called validators agree on the order and outcome of transactions. XRPL.org’s FAQ, checked September 29, 2026, counts 150+ validators, 35+ of them on the default trusted list, and says Ripple ran 1 of those 35 as of July 2023.
The full answer
How does the XRP Ledger reach agreement without mining?
The XRP Ledger uses its own consensus protocol. Ripple’s XRP page describes it as a mechanism Ripple calls Proof of Association. It sets it apart from proof-of-work and proof-of-stake blockchains. Ripple says servers called validators agree on the order and outcome of transactions every 3 to 5 seconds [2]. The speed is Ripple’s own figure. How fast a payment settles and what it costs is covered on what it costs to send XRP and how fast it is.
XRPL.org’s FAQ frames the problem being solved. It says proof of work was the first mechanism to solve the double-spend problem without a trusted third party. It also says the XRP Ledger’s consensus mechanism solves the same problem faster, cheaper and with less energy [1]. That comparison is the documentation’s own claim, not an independent measurement. The FAQ calls the XRP Ledger a decentralized, public blockchain [1]. The background on what the ledger is sits on what the XRP Ledger is.
XRPL.org puts it this way: “Confirming transactions does not require wasteful or competitive use of resources, unlike most other blockchain systems.”[7] Once a ledger version gathers enough agreement, XRPL.org says it is “considered validated” and “final.”[7]
A new ledger version becomes validated when enough of a server’s trusted validators agree on it.[7] XRPL.org says: “As long as fewer than 20% of trusted validators are faulty, consensus can continue unimpeded; and confirming an invalid transaction would require over 80% of trusted validators to collude.”[7]
Rule changes are called amendments, and “validators then vote on these changes.”[11] XRPL.org says “Operators of xrpld validators configure their servers to vote on each amendment”.[11] An amendment passes when it keeps “more than 80% support for two weeks”.[11] The amendment pages opened for this page describe votes by validator operators only; on our reading, holding XRP carries no amendment vote.
How many validators are there, and how many does Ripple run?
XRPL.org’s FAQ, checked on September 29, 2026, says there are 150+ validators on the network and 35+ on the default Unique Node List, the list of validators that servers trust unless their operators choose otherwise. The same FAQ says that, as of July 2023, Ripple ran 1 of the 35 validators on that default list [1]. The FAQ gives no date for the 150+ and 35+ counts. No newer public figure for Ripple’s share is known.
The FAQ says Ripple does not own or control the XRP Ledger or its network, and that its rights are the same as those of other contributors [1]. The FAQ also says Ripple contributes to the reference server software, rippled, and employs engineers who work on the open-source code [1]. Who funds that work is covered on who writes and pays for the XRP Ledger’s software.
XRPL.org says “This list is called a Unique Node List” (UNL).[7] Validators are servers specifically configured to take part in consensus.
It adds: “Typically, these lists are very similar to one another or even identical.”[8] In September 2025 the Foundation’s list moved to a new address and signing key after stewardship passed to a new XRPL Foundation.[9] Whether this arrangement gives the list publishers too much say is the subject of whether the default validator list makes the ledger centralized. ## Why do validators run nodes if they are not paid?
XRPL.org’s FAQ says running a validator requires no fees or XRP and costs about as much as running an email server. It names the main incentive as preserving the stable operation and sensible evolution of the network [1]. The FAQ says Ripple avoids paying XRP as a reward for running a validator so that rewards do not warp validator behaviour [1].
Because a validator needs no XRP and pays no fee to take part, the ledger’s security does not depend on validators locking up coins or burning energy. It depends on which validators each server operator decides to trust. No public source measures any business interest validators may have beyond the motive the FAQ names.
What does the protocol do if validators disagree or too many go offline?
XRPL.org says that if too many participants are unreachable or misbehaving, “the network fails to make progress rather than diverging or confirming invalid transactions.”[7] When no supermajority is clear from the validations received, XRPL.org says the previous consensus round was wasted and “a new round must occur before any ledger can be validated.”[5] The ledger’s record of halts and incidents is covered on whether the XRP Ledger has ever halted or forked.
XRPL.org says “If more than about 20% of validators are unreachable or not behaving properly, the network fails to reach a consensus.”[6] In that state, “new transactions can be tentatively processed, but new ledger versions cannot be validated, so those transactions’ final outcomes are not certain.”[6]
David Schwartz, whom Decrypt identified as Ripple’s CTO, said on X “It looked like consensus was running, but validations were not being published, causing the network to drift apart”, and that “It just caused ledgers not to be seen as trusted for about an hour”.[10] Other incidents are collected on the XRP Ledger’s outages and incidents.
XRPL.org says research showed that “in the worst case scenario, 90% overlap was required to prevent a fork.”[8] ## How does the cost to attack compare with proof-of-work and proof-of-stake chains?
XRPL.org’s FAQ says its consensus mechanism is faster, cheaper and more energy efficient than proof of work [1]. That is a claim about running costs. As of October 1, 2026, no public estimate exists of what it would cost to attack the XRP Ledger, nor of how that compares with attacking a proof-of-work or proof-of-stake chain.
Since the FAQ says validators stake no XRP and pay no fees [1], the question of attack cost on this ledger is about trust lists, not about buying hardware or coins. That follows from the facts cited above. Putting a number on it would need evidence that has not been published. A broader comparison of the two coins is on how XRP compares with Bitcoin.
XRPL.org says “No matter how many validating servers a would-be attacker runs, those servers have no say on what the existing participants consider validated unless those participants choose to trust the attacker’s validators”, and “The XRP Ledger is not vulnerable to a 51% attack because it does not use mining in its consensus mechanism.”[6]
Who decides which validators to trust, and what if Ripple misbehaves?
XRPL.org’s FAQ says validators can choose not to use the default list, or any widely used list, and that anyone can create a new list at any time [1]. It says that if Ripple stops operating or acts maliciously, participants can change their lists to one from a different publisher. It also says anyone can download and compile the software from source [1].
These statements make the default list a starting point rather than a rule of the protocol. No public source shows how many operators keep the default list or how quickly they could switch. How ledger rule changes are approved is covered on how XRP Ledger amendments are approved. Whether Ripple can freeze coins is answered on does Ripple control XRP.
What is the case against this design?
The evidence for and against it is weighed on whether the default validator list makes the XRP Ledger centralized. Two limits apply to this evidence. The figure for Ripple’s share of the default list dates from July 2023 [1]. The claims that the system is faster, cheaper and less energy-hungry come from the ledger’s own documentation [1]; Ripple separately describes its mechanism as unlike proof-of-work and proof-of-stake blockchains [2]. Neither source is an independent study. Whether the ledger’s keys are at risk from future computers is a separate question, covered on XRP and quantum computing risk.
What we know
- XRPL.org’s FAQ (undated, checked September 29, 2026) says there are 150+ validators on the network, with 35+ on the default Unique Node List (UNL).
- The same FAQ says that, as of July 2023, Ripple ran 1 of the 35 validators in the default UNL.
- Ripple’s XRP page (checked September 29, 2026) says XRP uses a consensus mechanism it calls Proof of Association, unlike proof-of-work or proof-of-stake blockchains, in which validators agree on the order and outcome of transactions every 3 to 5 seconds. That is Ripple’s own description of its mechanism.
- XRPL.org’s FAQ (checked September 29, 2026) says proof of work was the first mechanism to solve the double-spend problem without a trusted third party, and that the XRP Ledger’s consensus mechanism solves the same problem faster, cheaper and with less energy.
- XRPL.org’s FAQ (checked September 29, 2026) says running a validator requires no fees or XRP, costs about as much as running an email server, and that the main incentive is to preserve the network’s stable operation and sensible evolution.
- XRPL.org’s FAQ (checked September 29, 2026) says Ripple avoids paying XRP as a reward for running a validator so that such incentives do not warp validator behaviour.
- XRPL.org’s FAQ (checked September 29, 2026) says validators can choose not to use the default UNL, anyone can create a new UNL at any time, and if Ripple stops operating or acts maliciously, participants can switch to a list from a different publisher.
- XRPL.org’s FAQ (checked September 29, 2026) says Ripple does not own or control the XRP Ledger or its network, and that Ripple’s rights are the same as other contributors’.
- XRPL.org’s consensus page, checked September 29, 2026, says consensus continues while fewer than 20% of trusted validators are faulty, and confirming an invalid transaction would need over 80% of them to collude.
- September 18, 2025: XRPL.org announced that the default list moved to a new XRPL Foundation publisher address and key.
- Rule changes (amendments) pass after more than 80% of trusted validators support them for two weeks, according to XRPL.org’s amendments page, checked September 29, 2026.
- February 4, 2025: the ledger stopped validating new ledgers for about an hour, then recovered (Decrypt, February 5, 2025).
- XRPL.org’s consensus documentation says that if too many participants are unreachable or misbehaving, the network fails to make progress rather than diverging or confirming invalid transactions, and that when no supermajority is clear from the received validations, the round is wasted and a new round must occur before any ledger can be validated (XRPL.org).
What we reason Analysis
- The FAQ says running a validator requires no fees or XRP, so the ledger’s security does not rest on validators locking up XRP or spending on energy. It rests on which validators each server operator chooses to trust.
- The FAQ says validators can drop the default UNL and switch publishers, so the default list is a starting point, not a rule of the protocol. No public source shows how many operators actually change it.
- The FAQ says Ripple avoids paying validator rewards, so validators have no direct payment from the ledger. Their motive is the one the FAQ names, keeping the network stable, plus any business interest of their own, which no public source measures.
What's still open
- No public count of Ripple’s share of the default UNL newer than July 2023 was available as of October 1, 2026. The FAQ’s 150+ and 35+ figures are undated on the page.
- As of October 1, 2026, no public estimate of the cost to attack the XRP Ledger exists, nor a comparison with the cost to attack proof-of-work or proof-of-stake chains.
- As of October 1, 2026, no sourced critique of the default UNL’s concentration is public; the validator centralization page covers that debate.
- Searched:
In plain English
The XRPL.org FAQ says proof of work was the first mechanism to solve the double-spend problem without a trusted third party, and that the XRP Ledger’s consensus mechanism solves the same problem in a far faster, cheaper and more energy efficient way. The XRP Ledger works differently. A group of computers called validators compare notes and agree on which payments happened and in what order. Each computer owner picks which validators to trust, and the official documentation says Ripple ran 1 of the 35 on the default list as of July 2023. Validators are not paid for this work.
Key terms
Sources
- FAQ — XRPL.org, undated (checked September 29, 2026) Primary
- XRP — Ripple, undated (checked September 29, 2026) Company-reported
- Negative UNL — XRPL.org, read October 2, 2026 Primary
- About XRPL — XRP Ledger (xrpl.org), read 2026-10-02 Primary
- Consensus Principles and Rules — XRPL.org, read 2026-10-02 Primary
- Consensus Protections Against Attacks and Failure Modes — XRPL.org, read 2026-10-02 Primary
- Consensus — XRPL.org, undated (checked September 29, 2026) Primary
- Unique Node List (UNL) — XRPL.org, undated (checked September 29, 2026) Primary
- Default UNL Migration — XRPL.org, September 18, 2025 Primary
- XRP Ledger Temporarily Halts Block Production, Ripple CTO Cites Possible Network 'Drift' — Decrypt, February 5, 2025 Secondary
- Amendments — XRPL.org, undated (checked September 29, 2026) Primary
- Consensus Structure — XRPL.org, read 2026-10-03 Primary
- Network Security Economics | XRPL Settlement Mechanics | XRP Academy — XRP Academy, read 2026-10-03 Secondary
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
