New Feature for Banks on This Altcoin’s Network: Update Goes Live, but One Permission Comes with a Warning
As an update enabling banks and other institutions to delegate tasks on the XRP Ledger without sharing their master keys goes live, users have been advised to wait for a fix before using the token-burning permission.
According to a report by CoinDesk based on XRPL Dashboard data, PermissionDelegationV1_1 went live on October 8. The new feature allows an account owner to authorize other accounts to perform only specific transactions.
What changes for banks and stablecoin companies?
Institutions handling day-to-day transactions may need to keep signing keys continuously accessible. Keeping a key with broad permissions on internet-connected systems increases the risk in the event of a potential attack.
With task-based delegation, payments, customer approvals, and compliance operations can be assigned to separate accounts. For example, a stablecoin issuer can delegate customer approvals to a helper account while keeping its main account’s keys offline. This allows banks to apply on the network the same separation of duties they already use among staff.
Helper accounts sign transactions with their own keys and can use only the permissions granted to them. Each helper account can be assigned up to 10 permissions; the account owner can later change or revoke them. Permissions restrict transaction types but do not impose an automatic spending limit based on amount.
Fix awaited for token-burning permission
Official guidance says the PaymentBurn permission should not be delegated until a separate fix goes live. Intended to grant token-burning authority, this permission can also allow a helper account to create new tokens under certain conditions.
The issue concerns tokens issued on the XRP Ledger; it does not involve creating new XRP. Other detailed permissions are not affected by this issue.
On the Friday the source report was prepared, the fix had the support of 27 out of 35 validators. At least 29 supporters are required to start the two-week activation countdown. For network upgrades, validator support must remain above 80 percent for two weeks.
Developers are also investigating a separate bug that can exclude validators making routine security key changes from the vote count. This can make a proposal appear to have more support than it actually does; a proposed fix to track validators by their permanent identities is under review.