Is XRP Decentralized? Cyber Capital Founder Says It's 'Straight-Up Fraud'
Justin Bons says an emergency release shipped as closed-source binaries and a 35-validator default list undercut XRP's decentralization claims.
Key takeaways
- Thirty-five validators. Bons' infographic puts the published default list at 35 validators, all on version 3.4.1 while its source stayed unavailable.
- Two weeks closed. Bons says the ledger ran closed-source code for around two weeks, with the change expected to become mandatory on Friday, Oct. 9.
- The vote came first. His timeline has the amendment crossing the 80% threshold at 14:12:51 UTC on Sept. 25, with the public announcement about 35 minutes later.
What happened
Justin Bons, the founder of Cyber Capital, wrote on X that selling XRP to retail investors as decentralized is 'straight up fraud'. He cited the XRP Ledger's use of undocumented software code as evidence of flaws in its governance and consensus system.
Bons focuses on xrpld 3.4.1, the emergency version shipped on Sept. 25 to fix security-sensitive problems in the XRP Ledger's server software. According to the material he published, the release went out as binaries while the matching source code was withheld.
XRPL's release notice said the code would come out later with a retrospective, because disclosing the fix straight away could expose the vulnerability before validators upgraded. Bons does not dispute that security was the reason given.
Why it matters
Bons' research shows xrpld 3.4.0 was the newest tagged release available publicly on GitHub when he reviewed the repository on Oct. 8, while the validators he checked already ran 3.4.1. He argues this creates a trust problem, since operators had to run binaries they could not check against public source code, and he contrasted it with what he called better emergency practice on other networks.
The XRP Ledger depends on validators that individual participants must trust, unlike Bitcoin's Proof-of-Work system. Ripple and the XRP Ledger Foundation publish recommended validator lists that server configurations use by default, and anyone can run a validator without necessarily having a say in consensus.
The other question is who decides when a rule change takes effect. Bons describes Ripple and the XRP Ledger Foundation as 'kingmakers', saying control of that default trusted list gives the publishers outsized influence over whose validator votes count. The report notes that this is his interpretation of the governance model, not a neutral description of XRP Ledger consensus.
Timing is part of his argument. His timeline puts the fixBatchV1_2 amendment past the 80% threshold on the published validator list at 14:12:51 UTC on Sept. 25, with the public announcement of 3.4.1 about 35 minutes later, at 14:47:54 UTC. The amendment was expected to become mandatory on Friday, Oct. 9, if it stays adequately supported and activates, outdated servers will be amendment-blocked and unable to stay in sync with the network.
What the data shows
- Bons' infographic puts every validator on the published default list on version 3.4.1, with that build's source still not public at the time.
- His analysis separates the roughly 204 validators tracked by XRPScan from the much smaller published default list, which the infographic counts at 35.
- By Oct. 8, his data showed the amendment carried by all 35 validators on the published list, with no votes against it.
- In his review, Bons found the lists published at unl.xrplf.org and vl.ripple.com identical.
What is still unclear
- The reports do not say which vulnerability version 3.4.1 was meant to fix, or when the promised source code will be published.
- The reports do not say how many of the roughly 204 validators tracked by XRPScan sit on the published default list.
- The report describes Bons' account of a permissioned authority model as his interpretation, not a neutral description of XRP Ledger consensus.
Questions readers ask
What did Justin Bons say about XRP?
He wrote in a post on X that selling XRP to retail as decentralized is 'straight up fraud'. He pointed to the XRP Ledger's use of undocumented software code as evidence of governance and consensus flaws.
Why does Bons call the XRP Ledger centralized?
He points to the network's trusted validator list model, where Ripple and the XRP Ledger Foundation publish recommended validators used by default in server configurations. His infographic puts the published default list at 35 validators, against roughly 204 validators tracked by XRPScan.
What is xrpld 3.4.1?
It is the emergency update the XRP Ledger shipped on Sept. 25 for its server software. It handles security-sensitive problems and adds the fixBatchV1_2 amendment, and its source code was withheld at first.
What happens on Oct. 9?
If the amendment stays adequately supported and activates, outdated servers will be amendment-blocked and unable to stay in sync with the network. Bons says the change was expected to become mandatory that Friday.