Ripple has recommended stripping more than 10,000 lines of unused XChainBridge code from the XRP Ledger while its incoming Lending Protocol V1.1 undergoes an AI-only security review through Sherlock's Audit Engine. The dual push follows an earlier attackathon that found 94 valid issues, including 15 critical and 19 high-severity findings, and comes as the industry logged $1.31 billion in security losses in H1 2026.
Ripple wants to remove more than 10,000 lines of dormant code from xrpld while a separate AI-only audit tests the security of its upcoming native lending system. Ripple has recommended withdrawing the XChainBridge amendment (XLS-38), arguing that the code has become dead weight the network no longer needs to carry.
Axelar left XRPL with unused bridge code
XLS-38 was built to move assets between the XRP Ledger and connected sidechains through witness servers that observe transactions and attest to activity across networks. But Ripple chose Axelar for the XRPL EVM Sidechain instead, after weighing security, user experience, decentralization, and the operational burden of maintaining a bridge.
The company announced the Axelar decision in June 2024 but left XLS-38 open for a validator vote, giving developers roughly 12 to 15 months to show demand for private sidechains that specifically needed it. That demand never reached the level Ripple expected, leaving a large block of inactive code that still required maintenance and review.
As a result, Ripple now estimates that withdrawing XChainBridge and the related fixXChainRewardRounding amendment would eventually remove more than 10,000 lines from xrpld. The company cited maintenance burden, contributor complexity, and attack surface as the costs of keeping dormant functionality, and said XRPL should stay lean as the network evolves.
The change isn't immediate: Ripple controls one validator vote, and the proposal still has to clear the XRPL amendment process. If the community backs it, Ripple would first mark XChainBridge obsolete, and validators adopting that version would stop voting for the amendment, allowing removal once the network converges. Ripple also left the door open to reconsidering if developers can show concrete projects that still need XLS-38.
Lending draws heavier scrutiny
The cleanup comes as XRPL prepares to introduce lending infrastructure with far more financial interactions to secure. Lending Protocol V1.1 builds on Ripple's push to bring native borrowing and lending to XRPL alongside Single Asset Vaults, combining loan lifecycle management, interest-rate calculations, multi-party fee routing, credential-based permissions, and interactions with asset pools.
On Aug. 27, Sherlock said V1.1 had entered an intensive AI-only security review through its Audit Engine, which combines multiple AI auditors and frontier models with specialized security capabilities. Sherlock has not disclosed any findings or a completion date, saying a fuller account would follow once the process finishes.
The review follows an earlier attackathon that Ripple and Immunefi ran with a $200,000 prize pool in late 2025, covering 35,498 lines of code. That contest drew 455 submissions from 131 researchers and produced 94 unique valid findings, including 15 critical and 19 high-severity issues, all of which Ripple said it addressed. Between March and May, Ripple's AI red team filed 20 lending-specific tickets and confirmed seven bugs that were then fixed, including an inverted invariant that could have let phantom collateral go undetected and an integer-overflow issue that could have caused a node deadlock.
Industry losses keep pressure on code audits
The expanded XRPL security program comes as the broader industry keeps absorbing losses despite years of audits and bug bounties. CertiK recorded $1.315 billion in losses across 344 security incidents in the first half of 2026, with code vulnerabilities appearing in 204 incidents, the most frequent attack type. Excluding the exceptional $1.45 billion Bybit breach from a year earlier, CertiK calculated that comparable losses rose about 28% this year.
Ripple's own security researchers have cautioned against treating AI as a replacement for expert review, saying their AI pipelines produce false positives and that human validation still matters for subtle bugs a model can misread. That leaves Sherlock's AI-only engagement as a test of how far specialized models can extend protocol-security coverage, with its value ultimately resting on what it finds and whether those findings get fixed before V1.1 advances.
Source: CryptoSlate
Trading involves risk.