Ripple wants to remove more than 10,000 lines of dormant XChainBridge code from the XRP Ledger as Lending Protocol V1.1 enters an AI-only security review via Sherlock's Audit Engine. The two parallel tracks land as crypto platforms face what CertiK tallied as $1.315 billion in losses across 344 security incidents during the first half of 2026, with code vulnerabilities remaining the most frequent attack type. Both moves underscore how security posture is shifting ahead of XRPL's most financially complex feature to date.
Why it matters
The XChainBridge amendment (XLS-38) was originally designed to move assets between XRPL and connected sidechains through witness servers. After Ripple selected Axelar to power the EVM Sidechain in June 2024, the native bridge lost its principal use case. The 12-to-15-month window Ripple gave developers to surface demand for private sidechains requiring XLS-38 expired without delivering, leaving roughly 10,000 inactive lines to maintain, review, and patch in perpetuity.
Ripple's framing cuts to a structural point: XRPL should stay lean. A leaner code base shrinks the attack surface, lowers contributor onboarding friction, and reduces the chance a dormant amendment becomes the entry point for the next major breach. The proposal is not unilateral. Ripple controls only one validator vote, and the change is subject to the XRPL amendment process. If the community supports withdrawal, the bridge would first be marked obsolete before being removed in a later release once the network converges.
Market impact
On Aug. 27, Sherlock confirmed that Lending Protocol V1.1 entered an intensive AI-only review through its Audit Engine, a system that combines multiple AI auditors and frontier models with specialised security capabilities. Sherlock has not disclosed findings or a completion date, and has signalled a fuller account will follow once the process is finished.
The bet on AI is informed by a brutal track record. A $200,000 attackathon run with Immunefi in late 2025 covered 35,498 lines and drew 455 submissions from 131 researchers, producing 94 valid findings including 15 critical and 19 high severity. A subsequent AI-assisted red team filed 20 lending-specific tickets between March and May, surfacing seven confirmed bugs that included an inverted invariant allowing phantom collateral, a fee-free spam vector on loan payments, and an integer-overflow bug that could have triggered a node deadlock. Each fix shows that prior testing missed things no audit had caught.
Frequently asked questions
-
Why does Ripple want to remove XChainBridge from XRPL?
The XLS-38 native bridge lost its principal use case after Ripple selected Axelar for the EVM Sidechain in June 2024. A 12-to-15-month window for developers to demonstrate demand for private sidechains failed, leaving roughly 10,000 inactive lines to maintain and review in perpetuity.
-
What is Sherlock's role in the Lending Protocol V1.1 audit?
Sherlock is conducting an AI-only security review of Lending Protocol V1.1 through its Audit Engine, which combines multiple AI auditors and frontier models with protocol-tailored coverage. The review started Aug. 27. Sherlock has disclosed neither findings nor a completion date.
-
What kind of bugs did Ripple's earlier lending tests catch?
A late-2025 Immunefi attackathon produced 94 valid findings, including 15 critical and 19 high severity. A subsequent AI-assisted red team surfaced seven confirmed lending bugs, including an inverted invariant allowing phantom collateral, a fee-free spam vector on loan payments, and an integer-overflow bug that could…
-
How bad were crypto security losses in the first half of 2026?
CertiK recorded $1.315 billion in losses across 344 security incidents in H1 2026. Code vulnerabilities were the most frequent attack type, appearing in 204 incidents. Wallet compromises generated more than $444 million in losses on their own.
-
Does Ripple rely on AI alone for protocol security?
No. Ripple's lending pipeline layers independent audits, public security competitions, fuzzing, formal methods, community testing, and AI-assisted vulnerability discovery. Ripple's own researchers have cautioned that AI pipelines produce false positives and require human validation for subtle invariant bugs.
CryptoSlate