XRPL Says the Sponsored-Fees Bug Never Reached Mainnet
XRPL's Sept. 21, 2026 disclosure says an XLS-68 sponsored-fees bug stayed on Devnet. No funds were lost. Sponsor is not enabled on Mainnet.
XRPL Says the Sponsored-Fees Bug Never Reached Mainnet
A planned XRP Ledger feature would let another account pay your network fees and reserves. That feature is not enabled on Mainnet. Testers found a ledger-clutter bug on Devnet, and official records say no funds were lost.
What sponsored fees were supposed to do
XLS-68, titled Sponsored Fees and Reserves, describes a way for one account (the sponsor) to cover fees and reserves for another account (the sponsee). The user would still control their own keys. The specification is marked Final and was updated September 15, 2026.
A reserve is XRP the network locks so an account or ledger object can exist. The spec says sponsors can pre-fund a budget on the ledger or co-sign each transaction. The related protocol change is the Sponsor amendment.
That design is meant for apps that want people to transact without first buying spare XRP for fees. It is not a live Mainnet service today.
What XRPL disclosed on September 21, 2026
XRPL.org published "Vulnerability Disclosure Report: XLS-68 Sponsored Fees and Reserves" on September 21, 2026. The report says the issue was found during Devnet testing of the XLS-68 amendment in xrpld 3.3.0. The Sponsor amendment had not been activated on Mainnet.
Kris Dangerfield and Andrew Spencer reported it on August 7, 2026, with reproduction scripts and Devnet transaction hashes. The report also thanks Denis Angell of the XRPL Foundation.
The flaw was in how sponsorship ends. When a sponsor stopped covering the reserve on a specific ledger object, the software did not check whether the object's owner could cover that reserve. The obligation was removed, and the object could stay on the ledger with nobody backing it.
In testing, 30 permanent unbacked ledger objects were created using recycled capital at a cost of about 20 drops each. XRPL calls this a state-growth vector: cheap clutter that can persist. The report says there was no loss of funds, private-key compromise, or consensus failure, and that no funds were at risk.
The fix and the dates
The engineering response, per the disclosure, is a conditional exit. A sponsor cannot unilaterally end reserve sponsorship unless the sponsee can cover the reserve from their own XRP, another sponsor takes over through SponsorshipTransfer, or the sponsored object or account is deleted.
GitHub pull request 8044, "Enable reserve checking on ending sponsorship," was merged on August 18, 2026, and listed on the 3.4.0 milestone. The xrpld 3.4.0 release notes, published September 16, 2026, include the bug fix "Enabled reserve checking when ending a sponsorship," citing that pull request. The disclosure's timeline lists the 3.4.0 release as September 17, 2026. Both dates appear on official pages.
The disclosure says the Sponsor amendment will not be activated on Mainnet until the fix is included.
Mainnet status
The Known Amendments page listed Sponsor as introduced in 3.3.0 and open for voting at 17.14%, not enabled. It listed fixCleanup3_4_0, introduced in 3.4.0, as open for voting at 34.29%, not enabled. Those shares can change. Amendments on that page become enabled if they hold a supermajority for at least two weeks.
What remains unknown
CryptoWorkPro has not independently reproduced the Devnet test. Validator votes can move, so the percentages above are a snapshot from the Known Amendments page, not a prediction of activation. The disclosure's longer-term ideas, such as grace periods or reserve insurance pools, are described as uncommitted and would need their own specification process.
What to watch next
Check the Known Amendments page to see whether Sponsor or fixCleanup3_4_0 is still only open for voting, or has been enabled. Read later xrpld notes before treating any app that claims to pay your XRP fees as a live Mainnet feature. Ordinary XRP payments on Mainnet do not depend on this unfinished sponsorship path.
Sources
- XRPL.org, Vulnerability Disclosure Report: XLS-68 Sponsored Fees and Reserves, September 21, 2026: https://xrpl.org/blog/2026/vulnerabilitydisclosurereport-bug-aug2026
- XLS-68, Sponsored Fees and Reserves: https://xls.xrpl.org/xls/XLS-0068-sponsored-fees-and-reserves.html
- XRPL.org, Introducing XRP Ledger version 3.4.0, September 16, 2026: https://xrpl.org/blog/2026/xrpld-3.4.0
- XRPLF/rippled pull request 8044: https://github.com/XRPLF/rippled/pull/8044
- XRPL.org, Known Amendments: https://xrpl.org/resources/known-amendments
Disclosure: This article is informational coverage of XRPL's September 21, 2026 XLS-68 disclosure and the xrpld 3.4.0 notes. The illustration is generated artwork, not a photograph of a network event. Amendment votes can change, and this is not a live-network incident report. This article is not financial, legal, or investment advice. AI-assisted research and writing. Cited sources, not AI alone, support the claims.


