A $550,000 community audit contest uncovered two critical vulnerabilities in XRP Ledger features that could have drained user accounts without private keys. The findings reveal how Ripple’s audit-before-release model diverges sharply from the broader crypto industry’s patch-after-exploit norm.
Summary
- Sherlock’s two-week audit contest, which opened on April 13, 2026, uncovered 96 valid vulnerabilities across five proposed XRP Ledger amendments, including 2 critical and 6 high-severity bugs, before any of them reached mainnet.
- Ripple paid $309,000 in RLUSD bounties from a $550,000 prize pool, marking the first collaboration between Sherlock and Ripple and one of the largest…






