Ripple trims XRPL code as AI audits lending upgrade
Ripple recommended removing more than 10,000 lines of unused XChainBridge code from xrpld while Lending Protocol V1.1 undergoes an AI-only security review by Sherlock’s Audit Engine.
Ripple has recommended withdrawing the XLS-38 XChainBridge amendment and a related rounding fix, a change that would remove more than 10,000 lines of unused code from xrpld. The proposal follows limited demand for a native bridge after the company chose Axelar for the XRPL EVM Sidechain in June 2024.
XChainBridge was built to move assets between XRPL and connected sidechains using witness servers that observe transactions and attest across networks. The design was intended for private, permissioned and experimental sidechains. Ripple said larger witness sets can improve decentralization but raise coordination and governance demands, while smaller sets concentrate trust among operators as the value secured by a bridge grows.
The recommendation does not delete the code immediately. Ripple holds one validator vote and the amendment must pass the XRPL amendment process. If validators agree, Ripple plans to mark XChainBridge as obsolete; validators running software with that designation would stop voting for the amendment and the code could be removed in a later release once the network converges. Ripple will reconsider if developers present concrete projects that require XLS-38.
Separately, Lending Protocol V1.1 has entered an AI-only security review with Sherlock’s Audit Engine. The upgrade adds native borrowing and lending, loan lifecycle management, interest-rate calculations, multi-party fee routing, credential-based permissions and pool interactions. Sherlock began the engagement on Aug. 27 and has not released findings or a completion date. The Audit Engine runs multiple AI auditors and models and adjusts coverage to the protocol under review.
The V1.1 review follows extensive prior testing of the platform’s earlier lending features. In late 2025, Ripple and a bug-bounty partner ran a $200,000 attackathon covering 35,498 lines of code; the event produced 455 submissions from 131 researchers and 94 unique valid findings, including 15 critical and 19 high-severity issues. Ripple addressed those findings and then carried out additional audits, community testing, fuzzing and an AI-assisted red-team program.
Between March and May, Ripple’s AI red team filed 20 lending-specific tickets and confirmed seven bugs that were fixed. Reported issues included an inverted invariant that could hide phantom collateral, a fee-free spam vector involving loan payments, and an integer overflow that risked node deadlock. Ripple’s security work also patched public-facing crash paths, bounds-checking errors and cross-feature interactions identified through ongoing testing.
Industry data show a high volume of security incidents in 2026. A recorded report attributed $1.315 billion in losses to 344 security incidents in the first half of 2026, with code vulnerabilities appearing in 204 incidents. Reported wallet compromises accounted for more than $444 million in losses, and two protocol breaches together were listed at $576 million. Ripple’s security teams have said AI pipelines can produce false positives and that human review is required for subtle invariants and complex behavioral bugs.
Sherlock has not published results from the AI-only review. Ripple’s recommendation to withdraw XChainBridge remains subject to the amendment process while work on Lending Protocol V1.1 continues under multiple security reviews.








