Ripple is recommending removal of more than 10,000 lines of unused XChainBridge code from the XRP Ledger while its Lending Protocol V1.1 undergoes an artificial intelligence-only security review through Sherlock.
The code reduction targets XLS-38, the original bridge standard designed to enable asset movement between XRPL and connected sidechains through witness servers. Ripple chose Axelar for the EVM Sidechain after evaluating security, user experience, decentralization, and operational demands. The company gave developers 12 to 15 months from June 2024 to demonstrate demand for private sidechains requiring XLS-38. That demand failed to materialize.
Ripple identified maintenance burden, contributor complexity, and attack surface as costs of retaining dormant functionality. The company argued that XRPL should remain lean as the network evolves. The XChainBridge witness model carried trade-offs that became harder to manage as the value protected by a bridge increased.
The removal requires XRPL amendment process approval. If approved, code would first be marked obsolete, then removed in a later release once network converges. Ripple controls one validator vote. The company left open the possibility of reconsidering if developers demonstrate concrete projects requiring XLS-38.
Lending Protocol Security Testing
Lending Protocol V1.1 represents one of the most financially complex additions to XRPL since network launch, combining loan lifecycle management, interest-rate calculations, multi-party fee routing, credential-based permissions, and asset pool interactions. Sherlock’s Audit Engine combines multiple AI auditors and frontier models with specialized security capabilities.
Earlier lending and Single Asset Vault codebase underwent extensive security testing including an attackathon, audits, community testing, fuzzing, and AI-assisted red-teaming. The attackathon, run by Ripple and Immunefi in late 2025, offered a $200,000 prize pool and generated 455 submissions from 131 researchers covering 35,498 lines of code. The effort produced 94 unique valid findings, including 15 critical-severity and 19 high-severity findings.
Ripple’s AI red team filed 20 lending-specific tickets between March and May, identifying 7 confirmed bugs that were fixed. Sherlock did not disclose any findings or completion date for the V1.1 review.
Security Landscape Context
The first half of 2026 saw $1.315 billion in losses across 344 security incidents, according to CertiK incident tracking data. Code vulnerabilities accounted for 204 incidents. Wallet compromises resulted in $444 million in losses, while the combined losses from the Kelp DAO RPC compromise and Drift Protocol breach totaled $576 million.
Ripple’s security researchers cautioned against treating AI as a replacement for expert review, stating that AI pipelines produce false positives and human validation remains important for subtle bugs. Sherlock is conducting an AI-only review of Lending Protocol V1.1.