Key facts
- The XRP Ledger's Permission Delegation amendment is moving towards validator voting.
- Validator Vet has publicly supported the amendment, citing enhanced security for token issuers and treasury teams.
- The feature allows account owners to grant specific operational roles to trusted parties without revealing master keys.
- An independent security review by Cantina identified and verified fixes for high, medium, and low-risk issues.
- The amendment has passed XRPL quality assurance tests with no regressions.
The XRP Ledger's Permission Delegation amendment, a key component of xrpld version 3.3.0, is advancing towards a network-wide validator vote. This feature is designed to bolster security for institutional users, such as token issuers and treasury teams, by enabling account owners to delegate specific operational responsibilities to trusted parties without compromising their primary wallet keys.
Validator Vet has publicly declared his support for the amendment, voting 'Yes' and highlighting its critical nature for building secure operations on the XRP Ledger. He expressed gratitude to Cantina for a thorough security review that addressed previous issues, allowing for a more robust implementation. The system allows for the separation of sensitive account ownership from operational duties, mirroring the principle of separation of duties found in regulated financial institutions.
An independent security assessment conducted by Cantina between March 23 and April 8 identified nine findings, including two high-risk issues related to irrevocable delegated permissions after deletion and handling authorizations for delegated mint and burn operations. Both high-risk issues, along with medium and low-risk findings concerning permission validation, multisign behavior, and trustline controls, were resolved and verified by Cantina. The XRP Ledger Operations team confirmed that the amendment has passed the security review and XRPL quality assurance test suite, with no regressions found across 5,088 tests.