The XRP Ledger has restarted the activation process for a protocol change that would let one account assign narrowly defined responsibilities to another without giving up full control of its keys. The amendment, called PermissionDelegationV1_1, began a new 14-day activation window on Sept. 21 after winning support from 29 of the network’s 35 trusted validators.
If that backing stays above the required threshold for the full period, the upgrade could reach mainnet on Oct. 5 at 11:18 UTC. The proposal is the network’s second attempt to add delegated permissions after an earlier version was halted over a fee-draining vulnerability discovered during pre-mainnet testing.
How the activation process works
Under XRP Ledger’s amendment process, at least 80% of trusted validators must continuously support a change during a two-week countdown before it can activate. With 35 trusted validators in the current set, that means at least 28 must keep backing PermissionDelegationV1_1 for the clock to keep running.
The latest count cited in the activation window was 29 validators in favor. If support falls below the threshold at any point, the countdown resets rather than continuing toward activation.
What the upgrade would allow
The proposed feature is designed to let an account split authority by function. Instead of handing over a key that controls everything, an account could authorize another account to perform only a limited set of tasks.
Examples in the proposal include allowing a compliance system connected to the internet to approve customers to hold a stablecoin, while the keys with broader control remain offline. A separate operations account could also be allowed to make payments without gaining the ability to alter key settings or pass that authority on to someone else.
Each delegate can be granted up to 10 permissions, and the originating account would be able to modify or revoke those permissions later.
Why the first attempt was stopped
This is a revised version of an earlier delegated-permissions amendment that did not reach activation. The original design included a flaw that could have allowed an attacker to make another account absorb transaction fees for actions it had not validly signed.
According to the description of the issue, the software checked whether an account had permission to perform a transaction before it verified the signature. Because some failed transactions still incurred fees, an attacker could repeatedly submit transactions with intentionally high fees and potentially drain the victim account’s XRP balance before the invalid signature was caught.
What happens next
The vulnerability was reported by a community tester on Sept. 15, 2025, while the feature was being tested outside the main network. Validators were then advised to reject the original amendment, and it never went live.
The next confirmed milestone is the end of the current activation window. If validator support remains at or above the 80% threshold through the full 14 days, PermissionDelegationV1_1 could activate on the XRP Ledger mainnet as early as Oct. 5 at 11:18 UTC. If support drops below that level before then, the process would restart.
Source: www.coindesk.com