The XRP Ledger has implemented a new feature that enables account owners to grant specific permissions to other accounts without sharing their primary keys, enhancing security for financial operations.
This functionality allows businesses to assign limited tasks to separate accounts while keeping the main account's keys offline.
Reported by Shaurya Malwa on Oct 9, 2026, the new feature, known as PermissionDelegationV1_1, was activated on October 8. For an upgrade to proceed, it requires the backing of over 80% of trusted validators for a continuous two-week period. Currently, 29 out of 35 validators are needed to support the proposal.
The delegation process had to restart in September when support fell below the required threshold, as previously detailed by CoinDesk.
For businesses that engage in frequent cryptocurrency transactions, having signing keys accessible at all times is crucial. However, storing keys with extensive permissions on a device connected to the internet can increase vulnerability to hacking.
By utilizing delegation, companies can compartmentalize authority by task. For instance, a stablecoin issuer can permit a compliance account to validate new customers while keeping its primary keys secure. The account that is granted permission can perform only the actions it is authorized for, and the main account holder can modify or revoke these permissions as needed.
Each delegated account can be assigned up to 10 distinct permissions, which dictate the types of actions it can undertake instead of imposing a spending limit.
Financial institutions typically separate payment and compliance functions among staff, and this upgrade allows those divisions to be enforced directly within the ledger.
According to a report from Evernorth, an XRP treasury company, the network maintained an average of $3.72 billion in tokenized assets and $539 million in Ripple's RLUSD stablecoin during the second quarter, totaling approximately $4.26 billion.
Read More: XRP Ledger retries upgrade that lets banks split payment and compliance duties
In addition, users are advised against delegating the PaymentBurn permission until a separate fix is implemented. This permission is meant to allow a helper to destroy tokens, but under certain circumstances, it could also enable the creation of new tokens. This caution specifically pertains to tokens issued on the ledger rather than newly minted XRP, while other specific permissions remain unaffected.
Developers are currently investigating a bug related to how certain XRP Ledger servers tally votes. A report from October 8 pointed out that some servers may disregard a validator from their count if it changes its routine security key, despite being online and participating in the voting process.
If a server loses track of two validators, it would calculate support based on 33 instead of 35, which may misrepresent the actual status of a proposal's passage. A proposed solution is under review, aiming to have servers identify validators by a permanent ID.
As for the fix regarding the PaymentBurn issue, it garnered 27 out of 35 validator votes as of Friday, needing 29 votes to initiate the two-week countdown required to remove the warning.