Ripple is working to shrink the XRP Ledger’s attack surface by retiring unused native bridge code as it prepares to expand native lending under tighter security scrutiny. The company has recommended withdrawing XLS-38 (XChainBridge), estimating that removing the dormant feature and the related fixXChainRewardRounding amendment would eventually cut more than 10,000 lines from xrpld. RippleX engineer David Fuelling issued the formal recommendation on August 27, 2026, after a 12- to 15-month window following the June 2024 selection of Axelar for the XRPL EVM Sidechain failed to show meaningful demand for private sidechains that needed the native bridge. XLS-38 never activated on mainnet; only about 4–5 of 35 UNL validators were voting yes, well below the 80% support required for 14 consecutive days. Removal still depends on the XRPL amendment process, starting with marking XChainBridge obsolete so upgraded validators stop affirmative votes before later code deletion. In parallel, Lending Protocol V1.1 has entered an intensive AI-only review through Sherlock’s Audit Engine, following a late-2025 $200,000 attackathon that produced 94 unique valid findings and later AI red-team work that fixed seven confirmed bugs. The dual push coincides with $1.315 billion in industry losses across 344 security incidents in the first half of 2026, with code vulnerabilities the most frequent attack type.