Jump to content
The Coin Wire

Crypto moves, protocols and policy

XRP Ledger activates scoped account delegation, with one permission still risky

The XRP Ledger activated PermissionDelegationV1_1 on Oct. 8, letting account owners assign specific tasks to other accounts while retaining control of their main keys.

By The Coin Wire Editorial3 min read

XRP Ledger activates scoped account delegation, with one permission still risky

The XRP Ledger activated PermissionDelegationV1_1 on Oct. 8, letting account owners give other accounts authority to perform specific tasks without sharing their main signing keys, according to CoinDesk’s report on the activation. For businesses handling payments or issuing stablecoins, that creates a way to separate routine operations from the keys controlling larger holdings. The feature does not set a spending cap, and one permission remains subject to a warning.

What changed when the amendment went live?

PermissionDelegationV1_1 allows one account to authorize another to carry out specified actions using its own keys. The account owner can change or withdraw the permissions, while each delegated account can receive up to 10 permissions. Those permissions limit the kinds of actions a helper can take; they do not automatically limit how much value it can move.

That distinction matters for an issuer or financial institution trying to keep a main key offline while allowing staff or systems to handle day-to-day tasks. A compliance account, for example, could approve customers while a separate account handles payments. As CoinDesk reported, the arrangement makes divisions between those duties enforceable on the ledger, rather than relying only on an organization’s internal procedures.

The change followed an earlier attempt: the original PermissionDelegation amendment was disabled in version 2.6.1 because of a bug. The XRP Ledger’s amendment documentation says V1_1 replaces that implementation and fixes a critical bug found in it. The activation also followed a two-week validator supermajority process. CoinDesk reported that the network’s 35 trusted validators required at least 29 votes to meet the more-than-80% threshold.

How does delegation compare with other XRPL controls?

Delegation governs which actions another account may take on an owner’s behalf. Permissioned Domains, by comparison, govern access: an account must hold an accepted credential to use a restricted resource. XRPL documentation says a domain can accept between one and 10 credentials, but also says no current ledger features use domains; permissioned trading, vaults and lending are among features in development that could use them.

The two mechanisms therefore address different steps in a regulated workflow. Credentials can establish that an account meets an access rule; delegation can divide operational authority among accounts. Neither, by itself, proves that an institution has adopted the system or satisfies every legal obligation. The shift is in the ledger’s available controls, not evidence of bank uptake.

What risks and signals remain?

XRPL’s documentation warns users not to delegate the PaymentBurn permission until a separate fix activates. In certain circumstances, that permission—which is meant to let a helper destroy tokens—could also let it mint fungible tokens on the ledger. The warning does not apply to other granular permissions.

CoinDesk reported that the fix had 27 of 35 validator votes on Friday, Oct. 9, short of the 29 needed to begin its own two-week activation countdown. It also reported a separate issue under review: some servers may stop counting a validator after it changes a routine security key, and a proposed patch would identify validators by permanent ID instead. Those are the near-term checks on the upgrade: whether the PaymentBurn fix secures enough support, whether the counting patch advances, and whether institutions use delegated permissions while keeping their principal keys offline.

Source material