Crypto news report · source clearly identified
Ripple Targets XRP Ledger Code Bloat While AI Audits New Lending Protocol
Ripple plans to remove over 10,000 lines of unused XChainBridge code from the XRP Ledger and has launched an AI‑only security review of its Lending Protocol V1.1, amid a broader industry push to tighten code security.

Ripple is undertaking two parallel security initiatives on the XRP Ledger (XRPL). First, it is proposing to delete more than 10,000 lines of dormant XChainBridge code. Second, it has placed its upcoming Lending Protocol V1.1 under an AI‑only audit using Sherlock’s Audit Engine.
Removing unused bridge code
The XChainBridge (XLS‑38) was originally designed to move assets between XRPL and sidechains via witness servers. After Ripple selected Axelar for the XRPL EVM Sidechain, demand for the native bridge fell short of expectations. The resulting inactive code adds maintenance overhead and expands the network’s attack surface.
Ripple estimates that withdrawing the XChainBridge and the related fixXChainRewardRounding amendment would eliminate more than 10,000 lines from the xrpld codebase. The change will be submitted as an amendment and, if approved, will be marked obsolete before the code is finally removed in a later software release.
AI‑only audit of Lending Protocol V1.1
XRPL’s upcoming native lending infrastructure introduces complex financial interactions, including loan lifecycle management, interest‑rate calculations, multi‑party fee routing, and credential‑based permissions. To validate its security, Ripple engaged Sherlock’s Audit Engine for an intensive AI‑only review.
Sherlock’s platform combines multiple AI auditors and specialized security models, adjusting coverage based on the protocol under examination. No findings have been disclosed yet, and a full report will be issued after the review concludes.
Why the heightened scrutiny?
- In the first half of 2026, $1.31 billion was lost across 344 security incidents, with code vulnerabilities the most common attack vector.
- Previous audits of Ripple’s lending code uncovered critical and high‑severity bugs, prompting additional testing, fuzzing, and AI‑assisted red‑team exercises.
- Ripple’s own AI red‑team identified seven confirmed bugs in recent months, leading to fixes for issues such as phantom collateral detection, fee‑free spam vectors, and integer‑overflow conditions.
Multi‑layered security approach
Ripple emphasizes that AI tools complement, rather than replace, human expertise. Its security process includes independent audits, public bug‑bounty competitions, fuzzing, formal methods, community testing, and AI‑assisted vulnerability discovery. The company notes that AI pipelines can generate false positives, making human validation essential for subtle invariants.
Outlook
By pruning unused code and subjecting new financial features to rigorous AI‑driven analysis, Ripple aims to keep the XRPL lean and resilient as it expands native lending capabilities. The effectiveness of these measures will depend on the vulnerabilities uncovered and the speed with which they are addressed before V1.1 is deployed.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- August 28, 2026, 5:45 PM
- Original headline
- Ripple moves to shrink XRP Ledger attack surface as AI audit tests lending push