Ripple recommends stripping 10,000 lines of unused XRPL bridge code as AI audits its lending push

4 min read
Ripple recommends stripping 10,000 lines of unused XRPL bridge code as AI audits its lending push
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

XRP

Ripple has recommended stripping more than 10,000 lines of unused XChainBridge code from the XRP Ledger while its incoming Lending Protocol V1.1 undergoes an AI-only security review through Sherlock's Audit Engine. The dual push follows an earlier attackathon that found 94 valid issues, including 15 critical and 19 high-severity findings, and comes as the industry logged $1.31 billion in security losses in H1 2026.

Ripple wants to remove more than 10,000 lines of dormant code from xrpld while a separate AI-only audit tests the security of its upcoming native lending system. Ripple has recommended withdrawing the XChainBridge amendment (XLS-38), arguing that the code has become dead weight the network no longer needs to carry.

Axelar left XRPL with unused bridge code

XLS-38 was built to move assets between the XRP Ledger and connected sidechains through witness servers that observe transactions and attest to activity across networks. But Ripple chose Axelar for the XRPL EVM Sidechain instead, after weighing security, user experience, decentralization, and the operational burden of maintaining a bridge.

The company announced the Axelar decision in June 2024 but left XLS-38 open for a validator vote, giving developers roughly 12 to 15 months to show demand for private sidechains that specifically needed it. That demand never reached the level Ripple expected, leaving a large block of inactive code that still required maintenance and review.

As a result, Ripple now estimates that withdrawing XChainBridge and the related fixXChainRewardRounding amendment would eventually remove more than 10,000 lines from xrpld. The company cited maintenance burden, contributor complexity, and attack surface as the costs of keeping dormant functionality, and said XRPL should stay lean as the network evolves.

The change isn't immediate: Ripple controls one validator vote, and the proposal still has to clear the XRPL amendment process. If the community backs it, Ripple would first mark XChainBridge obsolete, and validators adopting that version would stop voting for the amendment, allowing removal once the network converges. Ripple also left the door open to reconsidering if developers can show concrete projects that still need XLS-38.

Lending draws heavier scrutiny

The cleanup comes as XRPL prepares to introduce lending infrastructure with far more financial interactions to secure. Lending Protocol V1.1 builds on Ripple's push to bring native borrowing and lending to XRPL alongside Single Asset Vaults, combining loan lifecycle management, interest-rate calculations, multi-party fee routing, credential-based permissions, and interactions with asset pools.

On Aug. 27, Sherlock said V1.1 had entered an intensive AI-only security review through its Audit Engine, which combines multiple AI auditors and frontier models with specialized security capabilities. Sherlock has not disclosed any findings or a completion date, saying a fuller account would follow once the process finishes.

The review follows an earlier attackathon that Ripple and Immunefi ran with a $200,000 prize pool in late 2025, covering 35,498 lines of code. That contest drew 455 submissions from 131 researchers and produced 94 unique valid findings, including 15 critical and 19 high-severity issues, all of which Ripple said it addressed. Between March and May, Ripple's AI red team filed 20 lending-specific tickets and confirmed seven bugs that were then fixed, including an inverted invariant that could have let phantom collateral go undetected and an integer-overflow issue that could have caused a node deadlock.

Industry losses keep pressure on code audits

The expanded XRPL security program comes as the broader industry keeps absorbing losses despite years of audits and bug bounties. CertiK recorded $1.315 billion in losses across 344 security incidents in the first half of 2026, with code vulnerabilities appearing in 204 incidents, the most frequent attack type. Excluding the exceptional $1.45 billion Bybit breach from a year earlier, CertiK calculated that comparable losses rose about 28% this year.

Ripple's own security researchers have cautioned against treating AI as a replacement for expert review, saying their AI pipelines produce false positives and that human validation still matters for subtle bugs a model can misread. That leaves Sherlock's AI-only engagement as a test of how far specialized models can extend protocol-security coverage, with its value ultimately resting on what it finds and whether those findings get fixed before V1.1 advances.

Source: CryptoSlate

Trading involves risk.

Most traded markets

XAU / USD
-3.13% 4,457.71
BRENT
-0.23% 90.630
BTC / USD
-3.28% 77,359.8
EUR / USD
-0.58% 1.15840
USTEC
-0.44% 29,432.88
PLTR
+0.62% 185.78
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.