The XRP Ledger's Permission Delegation amendment, included in xrpld 3.3.0, is progressing toward validator voting on the network. The proposed system introduces role-based authorization, allowing account owners to assign specific tasks to trusted operators without exposing the private keys of their primary wallets.
Targeting Institutional Operations
XRPL validator Vet confirmed support for the amendment on social media, stating that they voted yes on the proposal. Vet noted that the feature was heavily rewritten following issues identified last year and expressed gratitude to Cantina for providing a security review prior to the vote.
The amendment is designed to enhance security for token issuers and treasury teams by separating sensitive account ownership from operational responsibilities. Instead of sharing master account keys, organizations can keep their master keys in cold storage while granting specific functions to operational roles. Delegated permissions can cover compliance measures such as clawbacks, decentralized crypto exchange trading, and token minting, allowing teams to execute specific tasks without accessing employee accounts.
Independent Security Review by Cantina
An independent security assessment of the Permission Delegation amendment was conducted by Cantina between March 23 and April 8. The review identified nine findings, which included two high-risk issues, two medium-risk issues, three low-risk issues, and two informational observations, with seven issues addressed prior to the review.
The high-risk findings involved an irrevocable delegated permission after deletion and the handling of authorizations for delegated mint and burn operations. According to Cantina and XRP Ledger Operations, all findings were addressed in v1.1, verified by Cantina, and confirmed to have no regressions by the QA team across 5,088 tests. Corrections were also verified for medium- and low-risk findings, including permission validation, multisign behavior, and trustline controls.


