Ripple, the company behind the XRP Ledger (XRPL), has initiated a rigorous AI-only security audit of its new Lending Protocol V1.1. This move aims to strengthen the XRP Ledger attack surface by removing over 10,000 lines of unused XChainBridge code from the network.
The AI review, conducted by Sherlock’s Audit Engine, began on August 27, 2026. This parallel security initiative, which also bolsters XRP Ledger functionality, highlights Ripple’s determination to mitigate risks in an increasingly vulnerable crypto landscape.
Ripple initiates AI-only audit by removing legacy code to enhance XRPL security
Ripple’s recommendation to withdraw the XChainBridge (XLS-38) amendment will see over 10,000 lines of code removed from the xrpld server software. This move addresses a maintenance burden and potential attack surface posed by dormant functionality.
The original purpose of XLS-38 was to enable assets to move between XRPL and connected sidechains via witness servers. However, its primary use case—bridging the XRPL mainnet to the EVM Sidechain—is now handled by Axelar.
Broader developer demand for private sidechains specifically requiring XLS-38 never materialized. This lack of adoption meant the code remained a liability without serving its intended function.
The shift from XChainBridge to Axelar
Ripple announced its decision to use Axelar for the EVM Sidechain in June 2024, after evaluating factors like security, user experience, and decentralization. The XLS-38 witness model presented trade-offs, particularly as the value secured by a bridge increased.
Expanding the witness set would have increased decentralization but added complexity to governance and coordination. Conversely, a smaller group would have concentrated too much trust among operators, posing a security risk.
Withdrawing XLS-38 isn’t an immediate process. Ripple controls one validator vote, meaning the proposal must pass through the XRPL amendment process. If the community supports the change, Ripple plans to mark XChainBridge as obsolete, prompting validators to cease voting for its activation and allowing its eventual removal.
AI-only audit scrutinizes lending protocol V1.1
Reducing legacy code aligns with the XRPL’s preparation for its new lending infrastructure, a system that introduces considerably more complex financial interactions. The Lending Protocol V1.1 is now undergoing an intensive, AI-only security review by Sherlock’s Audit Engine.
This system uses multiple AI auditors and frontier models with specialized security capabilities. It adapts its coverage and depth to the specific protocol being examined, providing a cutting-edge, automated security analysis.
Sherlock has not yet disclosed any findings or a completion date for this audit. They stated a fuller account would follow once the process is complete, allowing for comprehensive review of any identified vulnerabilities.
This AI-only audit follows an already extensive security process for earlier versions of the lending and Single Asset Vault codebase. Repeated testing has been crucial, as vulnerabilities were found even after initial rounds of scrutiny.
Evolution of the Lending Protocol
The Lending Protocol V1.1 introduces fixed-term, uncollateralized loans, supported by off-chain underwriting and pooled liquidity in Single Asset Vaults. This structure differentiates it from many traditional overcollateralized DeFi lending platforms.
Previous reviews uncovered 94 security issues across all iterations of the protocol, which Ripple addressed. A re-audit by cybersecurity firm Halborn, completed by June 24, 2026, found no critical or high-severity vulnerabilities in the updated codebase.
The protocol also underwent formal verification with Common Prefix by June 9, 2026. This involved modeling the protocol and comparing it against the C++ server to identify edge cases and potential vulnerabilities.
Ripple and Immunefi previously conducted a $200,000 attackathon in late 2025, covering 35,498 lines of code. This initiative attracted 455 submissions from 131 researchers, yielding 94 unique valid findings, including 15 critical and 19 high-severity issues.
Ripple’s dedicated AI-assisted red team has also been active, uncovering more than 10 low-severity bugs since its inception. These identified issues are currently being prioritized and addressed by Ripple’s engineering teams. This proactive approach helps secure the altcoin market against early vulnerabilities before deployment.
Ripple’s broader AI red-team program also uncovered high-severity issues outside of lending. A security-focused xrpld release earlier this year incorporated fixes for public-facing crash paths and bounds-checking problems identified through this program.
These findings provide concrete justification for continuous and varied testing as Ripple refines V1.1. The company says the enhancement incorporates partner feedback and lessons learned from earlier implementations, ensuring a more robust final product.
Crypto industry grappling with persistent security threats
Ripple’s expanded security program comes amid a challenging industry-wide attack environment, where exploits remain costly despite years of bug bounties and audits. In the first half of 2026, CertiK recorded $1.315 billion in losses across 344 security incidents.
While this figure was lower than the previous year’s headline total, which included the $1.45 billion Bybit breach in H1 2025, comparable losses actually rose by about 28% this year. Code vulnerabilities were the most frequent attack type, accounting for 204 incidents.
CertiK also found that attackers are increasingly targeting older contracts, some more than a year old. This highlights how vulnerabilities can persist and remain exploitable long after software deployment, underlining the need for continuous vigilance.
Not all major losses stemmed from code flaws. Wallet compromises led to over $444 million in losses, while the Kelp DAO RPC compromise and Drift Protocol breach together accounted for $576 million. These incidents demonstrate that no single audit method can address every security threat.
This is why Ripple employs a multi-layered testing approach, rather than relying solely on AI. Its lending development process has included independent audits, public security competitions, fuzzing, formal methods, community testing, and AI-assisted vulnerability discovery.
Ripple’s own security researchers have cautioned against viewing AI as a complete replacement for expert human review. AI pipelines can produce false positives, and human validation is still crucial for subtle bugs that models might misinterpret.
The outcome of Sherlock’s AI-only engagement will offer valuable insights into how far specialized models can extend protocol-security coverage. Its ultimate usefulness will depend on the vulnerabilities it uncovers and how those findings translate into fixes before V1.1’s full rollout.
Outlook for XRP Ledger’s DeFi expansion
The intensive security efforts underscore Ripple’s commitment to growing the XRPL’s decentralized finance (DeFi) ecosystem. A successful and transparent AI audit could significantly strengthen the security case for its lending protocol, paving the way for broader adoption and increased capital flows.
The Lending Protocol V1.1 is currently tied to an amendment under validator voting for potential native integration into the XRP Ledger. Its mainnet deployment hinges on this approval, which will ultimately decide its fate within the ecosystem.
Meanwhile, the broader XRP market shows signs of renewed interest. XRP gained roughly 20% over the past week, briefly hitting $1.70 before pulling back to the $1.40-$1.45 range. It recently reclaimed its 200-day EMA at around $1.35, triggering a sharp short squeeze.
XRP-linked ETFs have recorded their seventh consecutive day of positive flows, attracting a combined $106 million in inflows over that period. This sustained interest suggests growing institutional confidence in the digital asset.
The SEC has also declared XRP treasury company Evernorth’s registration statement effective. This could lead to XRP Ledger DeFi leveraging liquidity from Evernorth’s initial reserve of 473 million XRP. Furthermore, on August 27, 2026, $26.2 million RLUSD was minted on the XRP Ledger, with its total circulating supply remaining above $2 billion, currently at $2.27 billion.
