XRP Ledger symbol beside a shield, an AI motif and a lending pathway

Ripple Targets 10,000 Lines of XRPL Code as AI Audit Tests Native Lending

August 28, 2026 7:08 pm Comments

Ripple is trying to make the XRP Ledger smaller before it makes the network’s financial machinery more ambitious.

The company has recommended withdrawing the dormant XChainBridge amendment, a move that could eventually strip more than 10,000 lines of unused code from xrpld. At the same time, XRPL Lending Protocol V1.1 has entered an AI-only security review through Sherlock’s Audit Engine.

Those two decisions point in the same direction: reduce the old attack surface while testing the new one before native lending reaches users.

Ripple wants dormant bridge code out.

CryptoSlate reports that XChainBridge was designed to connect XRPL with sidechains through witness servers that observe activity and attest to transactions. Ripple ultimately selected Axelar for the XRPL EVM Sidechain after weighing security, user experience, decentralization and the operational burden of running a bridge, while the expected demand for private sidechains using XLS-38 never materialized.

The company left the amendment available for roughly 12 to 15 months so developers could show a concrete need for it, but that use case did not emerge. Ripple now estimates that withdrawing XChainBridge and the related reward-rounding amendment would eventually eliminate more than 10,000 lines from xrpld, reducing maintenance work and the amount of dormant code security reviewers must keep checking.

That leaves developers maintaining and reviewing a large block of code without a clear production use. Ripple’s argument is straightforward: dormant functionality still costs engineering time, makes the codebase harder for contributors to understand and creates more places for vulnerabilities to hide.

The recommendation is not an instant deletion. In its technical explanation, RippleX says the validator-governed amendment process still controls what happens next.

XChainBridge would first be marked obsolete, validators would stop voting to enable it and the underlying code could be removed in a later release after the network converges.

Ripple also says it controls only one validator vote and has left room to reconsider if developers present concrete projects that still need XLS-38. The proposal therefore separates a recommendation to retire unused code from the community process required to carry it out.

The technical tradeoff goes beyond code size. A larger witness set can spread trust while adding coordination and governance complexity, whereas a smaller set is easier to operate but concentrates more trust among fewer parties.

That distinction matters. Ripple can recommend the cleanup, but it does not unilaterally rewrite the rules of the decentralized ledger.

Native lending is getting an AI-only review.

The cleanup arrives as XRPL prepares for a much more complicated feature set. Lending Protocol V1.1 is designed to support native borrowing and lending, with loan lifecycle management, interest calculations, credential-based permissions, fee routing and asset-pool interactions all living closer to the ledger.

On August 27, Sherlock said Ripple had begun an intensive AI-only review of the protocol through its Audit Engine:

Sherlock describes Audit Engine as a coordinated format that combines different AI security approaches and changes the depth of review around a protocol’s needs:

The test has a meaningful benchmark. According to CryptoSlate, earlier review rounds for XRPL lending surfaced 94 valid issues, including 15 classified as critical and 19 as high severity.

Ripple’s own security-first roadmap describes multiple review tracks on the road toward mainnet rather than treating one audit as a finish line.

The protocol has already moved through architecture review and competitive security work, with valid findings sent back into development rather than hidden behind a launch date. Lending V1.1 adds another focused review of the revised code and its financially sensitive interactions.

That sequence matters because a fixed version can introduce new behavior even after earlier findings are resolved. Repeated review gives researchers a chance to examine both the original design and the remediation work before validators are asked to support production amendments carrying live user funds at scale.

Why this matters for XRP.

Native lending could expand XRPL beyond payments and token transfers, potentially giving XRP and issued assets a larger role in onchain credit markets. But lending protocols also concentrate risk.

A flaw in pricing, permissions, accounting or liquidation logic can turn into a direct financial loss.

That is why the pairing here is more important than either headline by itself. Removing 10,000-plus lines of unused bridge code does not make the ledger invulnerable, and an AI audit does not guarantee that lending code is safe.

Together, however, they show a more disciplined approach: retire complexity that no longer earns its keep, then pressure-test the complexity the network actually wants to add.

Ripple’s account of its AI-assisted security work says the company has used specialized models to probe XRPL code while keeping human review, remediation and validator governance in the loop. It describes the technology as a way to expand coverage and surface unusual failure paths, not as an automatic certificate that a protocol is safe.

That framing is important because Sherlock has not yet published results from the Lending Protocol V1.1 review. The real proof will come when findings are disclosed, developers fix confirmed problems, follow-up checks verify those changes and validators evaluate the amendments that would put the lending system on the network.

XRPL’s lending push is moving forward while Ripple attacks technical debt at the same time. That is constructive progress, but the audit is still underway and no result has been announced.

The next question is not whether AI can find bugs. It is whether the full review process can find and fix the right ones before real money depends on the code.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.