Ripple’s Sherlock audit found 96 bugs before they reached a single wallet

1 hour ago 1



A $550,000 community audit contest uncovered two critical vulnerabilities in XRP Ledger features that could have drained user accounts without private keys. The findings reveal how Ripple’s audit-before-release model diverges sharply from the broader crypto industry’s patch-after-exploit norm. Summary Sherlock’s two-week audit contest, which opened on April 13, 2026, uncovered 96 valid vulnerabilities across five proposed XRP Ledger amendments, including 2 critical and 6 high-severity bugs, before any of them reached mainnet. Ripple paid $309,000 in RLUSD bounties from a $550,000 prize pool, marking the first collaboration between Sherlock and Ripple and one of the largest audit contests of 2026. The most severe finding was a signature-validation flaw in the Batch amendment that would have allowed attackers to execute transactions from any account without holding its private keys, first identified on February 19, 2026, by researcher Pranamya Keshkamat and Cantina’s AI tool Apex. A separate critical bug in Permission Delegation allowed malicious actors to silently drain XRP balances through repeated fee charges on invalid delegated transactions, because the code checked permissions ...

Read Entire Article