Debate surrounding the decentralization of XRP has intensified after the latest update to the XRP Ledger’s software. Justin Bons, founder of Cyber Capital, questioned the portrayal of XRP as a decentralized network for individual investors. He argued that parts of the network’s underlying code, which remain undisclosed, raise significant governance and consensus concerns.
Source Code Controversy Takes Center Stage
On September 25, XRP Ledger developers released an urgent update, version 3.4.1, for the server software, addressing critical security vulnerabilities and introducing the fixBatchV1_2 change. Although the update addressed sensitive security issues, the source code for these fixes has not been made public. The development team plans to release the code alongside a technical retrospective at a later date.
Justin Bons criticized the depiction of XRP as decentralized, arguing that undisclosed software code results in serious questions about the network’s operation.
Bons asserted that the XRP Ledger has been operating with closed-source code for nearly two weeks. He claimed that this change is expected to become mandatory by October 9, potentially leaving older software versions incompatible with the rest of the network unless supported and activated by the community.
UNL Model Under Renewed Scrutiny
Central to the decentralization debate is the XRP Ledger’s Unique Node List (UNL) model. Unlike Bitcoin‘s proof-of-work system, XRP Ledger relies on validators trusted by network participants. Ripple and XRP Ledger Foundation publish recommended validator lists, default options for server configurations. The XRP Ledger is the primary blockchain infrastructure for verifying transactions and maintaining consensus for the XRP ecosystem.
Technically, node operators can select any validators they wish. However, XRP Ledger documentation warns that a lack of common lists might isolate a node from the main network, making the influence of recommended validator lists a pivotal issue in this discussion.
Governance Criticism Intensifies
Bons contended that organizations publishing recommended validator lists wield excessive influence over the network. He argued that withholding the source code, albeit temporarily for security, creates unnecessary risk perceptions. This perspective reignites questions about the distributed nature of XRP Ledger’s governance model.
XRP Ledger developers confirmed that the source code for critical security patches is yet to be released and will be shared following a technical review.
A tension persists between the developers’ security-driven approach and critics’ transparency demands. This debate is expected to escalate in the coming days, contingent on whether the update becomes mandatory.



