The wait follows a much more serious problem found earlier this year. Researchers discovered a flaw in the original Batch proposal that could, under certain conditions, allow an attacker to include transactions from somebody else’s account without that person’s approval.
That version never reached the live network. Developers replaced it in the $XRP Ledger’s 3.3.0 software release on Aug. 6 and subjected the new version to another round of internal reviews, outside audits and public bug hunting.
The latest review found another 11 issues involving signatures, authorization checks and bugs that could crash servers. One flaw rated critical by security firm Common Prefix could have allowed an attacker to reuse a user’s signed permission to execute more transactions than intended.
RippleX said the review involved four senior engineers, audits from Halborn and Common Prefix, a public security contest and automated testing.
Meanwhile, RippleX says commercial projects using Batch are under contract or in development, although it has not named the companies as of Tuesday. CoinDesk asked RippleX which companies are waiting to use Batch and whether the 11 additional fixes were independently reviewed against the version validators are now voting on.
