Ripple, Immunefi Launch $200K Bug Hunt for XRPL’s New Institutional Lending Protocol
Researchers will focus on vulnerabilities that could threaten fund safety or protocol solvency.

What to know:
- Ripple is hosting a $200,000 "Attackathon" with Immunefi to test the XRPL Lending Protocol.
- The event invites white-hat hackers to find vulnerabilities in the protocol, which offers uncollateralized loans on the XRP Ledger.
- The XRPL Lending Protocol aims to bridge traditional credit markets with on-chain finance.
Fintech company Ripple is partnering with security platform Immunefi for an upcoming “Attackathon” event, designed to put a new decentralized finance protocol on the XRPL through rigorous testing.
The event will offer $200,000 in rewards to participants who help identify vulnerabilities in the proposed XRPL Lending Protocol, a new system designed to bring fixed-term, uncollateralized loans to the XRP Ledger.
Attackathon, which runs from Oct. 27 to Nov. 29, will invite white-hat hackers and security researchers to probe the codebase and report vulnerabilities before the protocol goes live.
Ripple will offer full educational support through an “Attackathon Academy,” including walkthroughs and Devnet environments, to help researchers get familiar with XRPL’s architecture. The learning stage runs from Oct. 13 to Oct. 27. Following this, the bug hunting competition starts Oct. 27 and continues through November, giving researchers ample time to thoroughly examine the protocol.
If a valid exploit is found, the entire reward pool unlocks. If not, $30,000 will be distributed to participants who contribute meaningful findings.
The XRPL Lending Protocol, governed under XLS-66, takes a different path from typical DeFi models. There are no smart contracts, wrapped assets, or on-chain collateral. Instead, creditworthiness is assessed off-chain, which allows financial institutions to apply their own risk models, while funds and repayments are recorded directly on the ledger.
It is an approach Ripple is pitching as a bridge between traditional credit markets and on-chain finance, offering transparency while keeping regulatory guardrails intact. Institutions that need collateralized structures can still manage those through licensed custodians or tri-party agreements, with the protocol acting as the execution layer.
Researchers will focus on vulnerabilities that could threaten fund safety or protocol solvency. In-scope targets include vault logic, liquidation and interest calculations, and permissioned access controls. Bugs must be reproducible and come with working proof-of-concepts to qualify.
The Attackathon covers several linked standards, including XLS-65 (single-asset vaults), XLS-33 (multi-purpose tokens), XLS-70 (credentials), and XLS-80 (permissioned domains).
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
BlackRock Files for Staked Ethereum ETF

The iShares Ethereum Staking Trust marks a bold push into on-chain yield exposure, as the SEC's tone has shifted under new leadership.
What to know:
- BlackRock has officially filed for a staked Ethereum ETF, marking its first formal move toward SEC approval.
- The filing reflects a shift in SEC policy under new Chair Paul Atkins after earlier pushback on staking features.
- BlackRock’s existing Ethereum fund holds $11B in ETH, but the new ETF would offer separate staking exposure.











