His criticism centers on xrpld version 3.4.1, an emergency software release distributed in late September. XRPL developers temporarily withheld the relevant source code because the update addresses undisclosed security vulnerabilities, while asking node operators to install the binary immediately.
The official release says fixBatchV1_2 has secured the required validator support. Once activated, servers that have not upgraded to version 3.4.1 are expected to become amendment blocked and unable to remain synchronized with the network.
Bons Targets XRPL’s Closed-Source Fix
Bons argues that requiring operators to temporarily run software they cannot fully inspect conflicts with the transparency normally associated with open-source blockchains.
XRPL developers say the measure is temporary and security-driven. Publishing the vulnerability-related changes before enough of the network upgrades could expose unprotected servers to attack.
The emergency release was issued specifically to give operators time to update before the Oct. 9 activation.
Developers have said the source code and a technical retrospective will be published once disclosure no longer creates the same security risk.
The dispute arrives while XRPL is simultaneously rolling out broader protocol upgrades, including batch transactions and delegated permissions that expand what accounts can do onchain.
Is XRP Ledger Permissioned?
Bons goes beyond the temporary closed-source patch.
He argues that XRPL resembles a Proof-of-Authority system because servers commonly rely on recommended Unique Node Lists published by Ripple and the XRP Ledger Foundation.
XRPL documentation confirms that UNLs determine which validators an individual server trusts. Strong overlap between those lists is also important for maintaining consensus and reducing the risk of incompatible ledger histories.
However, calling XRPL fully permissioned oversimplifies the architecture.
Anyone can operate an XRPL validator, server operators can select their own trusted validators, and Ripple cannot independently approve amendments across the network.
The broader debate over validator control also includes the fact that Ripple itself operates only one validator on a commonly used recommended list.