The XRP Ledger (XRPL) activated the PermissionDelegationV1_1 update this Thursday (8), which allows other accounts to be authorized to execute specific operations without sharing the main keys. The feature came into effect after approval by validators, but arrived accompanied by an official warning: one of the permissions can allow improper issuance of tokens until an additional fix is activated.
The update allows granting up to ten permissions per delegated account, with authorizations for activities such as payments and customer approval. The owner retains control of the original account and can modify or revoke access through a transaction called DelegateSet.
The change allows separating operational functions at financial institutions, stablecoin issuers, and tokenized asset platforms. A company can, for example, authorize an account to carry out compliance procedures without granting access to the keys used to manage its assets.
However, the delegation restricts types of operations, not financial amounts. Granting authorization for payments does not automatically establish a cap on transfers. The documentation also clarifies that the available permissions are predefined and do not allow, for example, restricting transactions exclusively to certain currencies.
PaymentBurn permission can allow improper issuance of tokens
The main warning involves the PaymentBurn permission, intended to authorize the destruction of tokens. According to the official documentation, under certain circumstances, an account with this authorization can also issue new fungible tokens, even without receiving specific permission for that operation.
The vulnerability affects tokens issued on the XRP Ledger, including assets associated with trust lines and Multi-Purpose Tokens (MPTs). The problem does not allow creating new XRP units, and the other granular permissions are not affected.
The official recommendation is not to delegate PaymentBurn until the fixCleanup3_4_0 update is activated, developed to prevent this authorization from being improperly used in asset issuance.
The new feature replaces a previous delegation implementation that had been disabled in 2025 due to another critical flaw. The vulnerability related to PaymentBurn is distinct from that problem.
According to CoinDesk, this Friday (9), the fix recorded 27 votes among 35 validators, below the 29 needed to start the two-week approval period. Until the corrective amendment takes effect, the restriction remains recommended for accounts that use the new feature.



