Ripple removes 10K lines of XRP Ledger code ahead of AI-audited lending launch
In brief
- Ripple recommends removing 10,000+ lines of unused XChainBridge code to reduce attack surface
- Lending Protocol V1.1 entered AI-only security review through Sherlock's Audit Engine on Aug. 27
- Private sidechain demand failed to justify retaining dormant bridge functionality
- Lending system is XRPL's most financially complex addition since launch
- Proposal requires XRPL community amendment vote to proceed
Closing the Bridge Gap
Ripple recommended removing more than 10,000 lines of unused XChainBridge code from the XRP Ledger. XChainBridge was designed to let assets move between XRPL and connected sidechains through witness servers that observe transactions and validate cross-chain transfers.
The company announced its decision to use Axelar in June 2024 for the EVM Sidechain but kept the older bridge available for a validator vote and gave developers 12 to 15 months to demonstrate demand for private sidechains. That demand failed to reach the level Ripple expected.
Ripple identified maintenance burden, contributor complexity, and attack surface as costs of retaining dormant functionality, arguing that XRPL should remain lean as the network evolves. The recommendation does not remove XChainBridge immediately. Ripple controls one validator vote, and the proposal remains subject to the XRPL amendment process, requiring community support to proceed.
Lending Under the Microscope
Lending Protocol V1.1 underwent an AI-only security review through Sherlock's Audit Engine on August 27. The underlying architecture combines loan lifecycle management, interest-rate calculations, multi-party fee routing, credential-based permissions, and interactions with asset pools.
Ripple has described the lending system as one of the most financially complex additions developed for XRPL since the network launched. The scale of that complexity justifies the audit approach. Sherlock's Audit Engine combines multiple AI auditors and frontier models with specialized security capabilities, adjusting coverage and depth based on code risk profiles.
Sherlock has not disclosed any findings or a completion date for the V1.1 security review. The timing matters — more than $1.31 billion was lost across 344 security incidents in the first half of 2026, underscoring the stakes for new DeFi infrastructure on any blockchain.
Frequently asked questions
Why is Ripple removing XChainBridge code?
Demand for private sidechains requiring XChainBridge failed to materialize as Ripple expected. The company identified maintenance burden, contributor complexity, and expanded attack surface as costs of keeping dormant code, preferring to keep XRPL lean.
What is Lending Protocol V1.1?
It's a native lending system for XRPL that combines loan lifecycle management, interest-rate calculations, multi-party fee routing, credential-based permissions, and asset pool interactions. Ripple calls it one of the most financially complex additions to XRPL since launch.
How is the lending protocol being audited?
Lending Protocol V1.1 entered an intensive AI-only security review through Sherlock's Audit Engine on August 27. The system combines multiple AI auditors and frontier models with specialized security capabilities, though Sherlock has not yet disclosed findings or a completion date.


