en
Back to the list

XRP Ledger is one vote away from starting its next big payments upgrade

source-logo  coindesk.com 3 h
image

An $XRP Ledger upgrade designed to bundle linked payments together is now one validator vote short of beginning its activation process after developers fixed 11 more bugs in the software.

RippleX, the developer team at payments company Ripple, detailed the latest repairs Monday in a review of Batch V1.1, a feature that has yet to go live on the $XRP Ledger.

Batch would let users combine as many as eight transactions into one operation. Two people swapping tokens, for example, could make sure both transfers complete together instead of one person sending funds only to find the other side failed.

The upgrade had support from 27 of 35 trusted validators in a Tuesday snapshot, or roughly 77%. $XRP Ledger changes need 80% backing, a threshold set so that alterations to the network only take effect when almost every trusted operator agrees. That makes a single holdout decisive at this stage, and one more vote would start the two-week countdown toward activation.

The Batch V1.1 amendment shipped in xrpld 3.3.0 and is now up for voting.

After the v1.0 signature bug was caught in February (pre-Mainnet, no funds at risk), we rebuilt it: root-cause fix, 4 senior reviewers, a Sherlock attackathon, and audits from Halborn and Common Prefix. We…

— Mayukha Vadari (@msvadari) September 14, 2026

Support must remain above that threshold for the full 14 days before the change takes effect, and validators can change their votes during that period.

The wait follows a much more serious problem found earlier this year. Researchers discovered a flaw in the original Batch proposal that could, under certain conditions, allow an attacker to include transactions from somebody else's account without that person's approval.

That version never reached the live network. Developers replaced it in the $XRP Ledger's 3.3.0 software release on Aug. 6 and subjected the new version to another round of internal reviews, outside audits and public bug hunting.

The latest review found another 11 issues involving signatures, authorization checks and bugs that could crash servers. One flaw rated critical by security firm Common Prefix could have allowed an attacker to reuse a user's signed permission to execute more transactions than intended.

RippleX said the review involved four senior engineers, audits from Halborn and Common Prefix, a public security contest and automated testing.

Meanwhile, RippleX says commercial projects using Batch are under contract or in development, although it has not named the companies as of Tuesday. CoinDesk asked RippleX which companies are waiting to use Batch and whether the 11 additional fixes were independently reviewed against the version validators are now voting on.

coindesk.com