
XRP Ledger Revives Upgrade to Separate Payment and Compliance Roles
Key Takeaways
- PermissionDelegationV1_1 upgrade could activate on October 5 to replace an earlier proposal blocked by a security flaw.
- The feature would let institutions grant limited account permissions without sharing keys that provide full account control.
- The revised upgrade fixes a flaw in an earlier version that could have drained XRP balances through unauthorized transaction fees.
XRP Ledger developers introduced an upgrade that could soon let banks and token issuers assign payment and customer-approval duties to employees or service providers without giving them full account control.
The revised upgrade, PermissionDelegationV1_1, entered a 14-day activation countdown on September 21, with support from 29 of the network’s 35 trusted validators, according to the live amendment dashboard. It replaces the original PermissionDelegation proposal and fixes a critical vulnerability discovered before that version reached mainnet.
The revised upgrade should maintain support from at least 28 validators for two consecutive weeks, as any drop below that level resets the countdown.
Separating Payments From Compliance
The upcoming PermissionDelegationV1_1 upgrade implements the XLS-0075 standard on the XRP Ledger. It lets account owners assign different permissions to separate accounts.
Under the XLS-0075 standard, an issuer could give an employee’s account payment permissions to manage trust lines, and a verification provider’s account permission only to authorize trust lines.
For instance, a stablecoin issuer could use an online compliance system to authorize customers’ trust lines while keeping its full-control keys safely offline.
Trust lines are ledger relationships used to hold issued tokens, while authorization controls can restrict which customers may hold them.
Account owners would use a DelegateSet transaction to grant a delegate up to 10 permissions, which they could later change or revoke, according to XRPL documentation.
This arrangement could limit the damage from a compromised operational key while allowing keys with full control to remain offline.
Why the Original Upgrade Was Blocked
The original version contained a flaw that allowed attackers to force unsigned transactions on a victim’s account. Repeated submissions carrying high fees could drain the victim’s XRP account balance.
The XRPL vulnerability report states the issue was discovered during devnet testing on September 15, 2025. The feature had not been activated on the mainnet, and validators were advised to oppose it. The developers subsequently disabled the original amendment in version 2.6.1.
The revised upgrade was included in xrpld 3.3.0. It addresses the fee-charging flaw in the original implementation.
Get started on WEEX with a simple 40 USDT reward. Deposit 100 USDT, make your trade, and claim the bonus.
Disclaimer: All content on The Moon Show is for informational and educational purposes only. The opinions expressed do not constitute financial advice or recommendations to buy, sell, or trade cryptocurrencies. Trading involves significant risk and may result in substantial losses. Always seek independent financial advice before making investment decisions. The Moon Show is not responsible for any financial losses or decisions made based on the information provided.
Please view the full disclaimer at: https://themoonshow.com/disclaimer


