2 min read
Add as a preferred source on Google

XRP Ledger Publishes Code After Emergency 3.4.1 Security Update

The release addressed two security-sensitive issues and introduced the fixBatchV1_2 amendment, which activated on Mainnet Oct. 9.

Mentioned assets
Unmarked validator hardware beside a secured circuit board / TokenPost.ai
Unmarked validator hardware beside a secured circuit board / TokenPost.ai

The XRP Ledger published the source code and vulnerability details for its emergency xrpld 3.4.1 update on Oct. 9, after operators had been asked to install the release before the code became public.

The update, released Sept. 25, addressed two security-sensitive issues and introduced the fixBatchV1_2 amendment. The amendment activated on Mainnet Oct. 9. Operators had to upgrade to version 3.4.1 or a later release to remain synchronized with the network.

The disclosed issues involved validation of Batch inner-transaction wrappers and an integer-overflow vulnerability in the XRP payment engine. The disclosure found no loss of funds, compromise of private keys or consensus failure.

More than 80% of validators on the default Unique Node List, or UNL, were running version 3.4.1 or later by Sept. 25. Separately, amendments require more than 80% support from trusted validators for two weeks before activation.

The episode highlighted questions about the XRP Ledger’s decentralization model. The network uses Unique Node Lists to identify validators trusted by each server. Operators can choose their own lists, while the default configuration uses lists published by the XRP Ledger Foundation and Ripple.

Anyone can operate a validator, but different UNLs need sufficient overlap to avoid a fork. The XRP Ledger has more than 150 validators, with more than 35 on the default list. Ripple operates one validator on that list.

Cyber Capital founder Justin Bons characterized the default validator lists and emergency upgrade process as evidence of practical control inconsistent with permissionless decentralization. The XRP Ledger’s stated model allows participants to run validators and select alternative UNLs, while warning that configurations with insufficient overlap can create operational risks.

The Oct. 9 publication made the source for xrpld 3.4.1 available after the emergency binary had already been distributed. Older servers that did not upgrade were unable to remain synchronized once the amendment activated.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…