Invest1 publisherNot yet confirmed elsewhere3 min readPublished
XRP Ledger delegation goes live with its PaymentBurn fix two validator votes short
XRP Ledger activated PermissionDelegationV1_1 on Oct. 8, letting account owners hand specific jobs to helper accounts while their main keys stay offline. Until a fix for a token-burning flaw activates, operators can safely hand off fewer jobs than the feature allows.
The Investor · Invest desk

What happened
- Each helper account can hold up to 10 permissions, and those restrict the kinds of action it may take without automatically imposing a spending cap.
- Official guidance says not to delegate PaymentBurn, because under certain conditions it lets a helper create issued tokens as well as destroy them; XRP itself is not affected.
- The fix for PaymentBurn had 27 of 35 validator votes on Friday and needs 29 to start the two-week countdown to activation.
- A bug report filed Oct. 8 found some servers drop a validator from their vote count after it rotates a routine security key, even while it keeps voting.
- The ledger averaged $3.72 billion in tokenized assets and $539 million in RLUSD during the second quarter, according to an Evernorth report.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure A stolen helper key can use every action type it was granted at any size, so an operator delegating payments has to set amount limits outside the ledger permission.
- constraint Token issuers keep the burn job with their main keys until the fix activates, so destroying tokens still means bringing the offline keys into use.
- precedent Delegation's own countdown reset in September when support slipped, so operators cannot yet put a date on when PaymentBurn becomes safe to delegate.
More than 80% of trusted validators for two straight weeks becomes a headcount once the list is 35 long, and the headcount is 29 [2]. Twenty-eight would be exactly 80%, and the rule says more than; 29 is about 82.9% [14]. The PaymentBurn fix stood at 27 on Friday, about 77.1% [8][15]. Two more votes start a 14-day clock, so the warning lifts no sooner than two weeks out, or rather two weeks after whichever day the 29th validator signs on [16].
The scoring bug in the Oct. 8 report bears on that count [10]. A server that loses track of two validators measures support against 33 instead of 35, and CoinDesk reported that this can make a proposal look closer to passing than it is [11]. If neither dropped validator was among the fix's 27 supporters, that server would show 27 of 33, about 81.8% and over the bar, while the true figure is 77.1% [17]. A patch that would identify validators by a permanent ID is still under review [11].
The case for delegation is about hot keys. A business signing all day needs keys online, and a broad key on an internet-connected machine raises the damage a hacker can do [12]. Delegation splits that authority by job: the helper signs with its own keys, can do only what it was granted, and the owner can change or withdraw the grant [5]. Banks already divide payment and compliance work among staff, and the ledger can now enforce the split [13]. About $4.26 billion of tokenized assets and RLUSD sat on the ledger on average in the second quarter, by Evernorth's count [9].
Operators face two limits on what they can hand off, and the PaymentBurn flaw should be the shorter-lived one. Its fix is two votes from a countdown [16], and other permissions are unaffected [7]. The missing spending cap is part of how grants work, since permissions restrict action types and impose no automatic cap [4]. CoinDesk's account does not mention any amendment that would add amount limits. I'd expect the first institutional delegations to go to compliance, a stablecoin issuer approving new customers from a helper account while its main keys stay offline [6], because a customer approval moves no money.
That view can miss in a few ways. The fix could reach 29 within days and lift the burn warning about two weeks later [16]. Support could fall back below 29 and restart the clock [2]. Or an issuer could fund a smaller operating account, delegate payments from it, and treat that balance as its cap. The last case would prove the view wrong, and it would show up as issuers granting payment permissions before any amount limit exists on the ledger.
What to watch
- Whether the PaymentBurn fix gains the two votes it needs to reach 29 of 35 and then holds them for the full two weeks.
- Whether the patch identifying validators by permanent ID clears review, so server tallies stop undercounting validators that rotate keys.
- Whether issuers' first delegations go to compliance or payment helpers, and whether any amendment proposes amount limits for delegated accounts.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption15
- Hype gap+10
- Incentives40
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The XRP Ledger activated PermissionDelegationV1_1 on Oct. 8, according to monitoring site XRPL Dashboard, allowing account owners to authorize other accounts to perform specific tasks without sharing their primary keys.
- [2]
XRP Ledger upgrades require more than 80% support from trusted validators for two straight weeks; with the current list of 35, that means at least 29 supporters.
- [3]
Delegation's countdown reset in September after validator support slipped below the required level.
- [4]
Each helper account can receive up to 10 permissions; these restrict the kinds of actions it can perform rather than automatically imposing a spending cap.
- [5]
The helper signs with its own keys, can perform only the actions it has been granted, and the owner can change or withdraw those permissions.
- [6]
A stablecoin issuer can allow a compliance account to approve new customers while keeping its main keys offline.
- [7]
Official guidance tells users not to delegate PaymentBurn, intended to let a helper destroy tokens, until a separate fix activates, because under certain conditions it also allows the helper to create new tokens; the warning concerns tokens issued on the ledger rather than newly minted XRP, and other granular permissions are unaffected.
- [8]
The fix for the PaymentBurn issue had 27 of 35 validator votes on Friday and needs 29 to start the two-week countdown that would lift the warning.
- [9]
The XRP Ledger held an average of $3.72 billion in tokenized assets and $539 million in Ripple's RLUSD stablecoin during the second quarter, about $4.26 billion together, according to a report Evernorth shared with CoinDesk.
- [10]
A report filed on Oct. 8 found that some XRP Ledger servers can drop a validator from their vote count after it changes a routine security key, even though it is still online and voting.
- [11]
A server that loses track of two validators would measure support against 33 instead of 35, which can make a proposal look closer to passing on that server's count than it really is; a proposed patch would identify validators by a permanent ID and is still under review.
- [12]
Businesses making routine crypto transactions need signing keys available throughout the day, and keeping keys with broad powers on an internet-connected computer increases the damage a hacker could cause if that computer is compromised.
- [13]
Banks already separate payment and compliance duties among staff; the upgrade gives businesses a way to make those divisions enforceable on the ledger itself.
- [14]
28 of 35 validators is exactly 80%, which does not meet a more-than-80% rule; 29 of 35 is about 82.9%.
- [15]
The PaymentBurn fix's 27 of 35 votes is about 77.1% support.
- [16]
The PaymentBurn fix needs two more validator votes, and the warning can lift no sooner than two weeks after the 29th vote arrives.
- [17]
On a server that has dropped two validators that were not among the fix's supporters, 27 votes against 33 is about 81.8%, above the 80% bar, against a true 27 of 35 at about 77.1%.
Sources
1 independent publisher whose own reporting we read for this story.
- coindesk.comXRP Ledger adds new controls for banks, stablecoins and tokenized funds
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Entities
- XRP LedgerFollow
- PermissionDelegationV1_1Follow
- RippleFollow
- RLUSDFollow
- Evernorth HoldingsFollow
- XRPL DashboardFollow