David Schwartz, co-founder of the XRP Ledger and Ripple Chief Technology Officer Emeritus, has proposed a transaction reservation system to mitigate front-running and sandwich attack risks on the XRPL native decentralized exchange and automated market maker.
The mechanism aims to protect regular network participants from sophisticated trading exploits by reshaping transaction processing order before ledger finalization.
Technical Blueprint Addresses Structural Vulnerabilities
According to analytics platform XRPresso.
io, validators and nodes can inspect pending requests in the pre-validation queue, allowing sophisticated actors to place competing orders ahead of retail users.
Schwartz responded to vulnerability claims by introducing a prioritization scheme, though he downplayed the immediate threat. "I'm not that concerned about this issue," he stated.
The architecture features two primary protocol additions: a ledger object named ReservedTxns and a new transaction type designated as TxnReserve.
Under the specifications, users can reserve an execution slot up to 16 ledgers in advance by supplying a target sequence number and paying at least twice the standard transaction fee.
"I have a proposal for a fairly simple scheme that would eliminate this attack.
It's a transaction reservation scheme that can ensure that a transaction executes before any transaction that was formed after it was disclosed," Schwartz added.
The system limits each future ledger to a maximum of 32 reserved transactions, which execute sequentially ahead of the standard public queue during consensus processing.
To prevent malicious actors from monopolizing the mechanism, the design incorporates an economic defense that scales fees upward as available reservation slots become occupied.
"This guarantees that you can execute your transaction ahead of any transaction that was formed after your transaction was disclosed," Schwartz said.
Server software would hold these prioritized actions until the exact moment key consensus data from the previous ledger is established, compressing the pre-execution visibility window available to external observers.
"You would use this approach any time you want to perform a transaction that you want to ensure cannot be sandwiched or front run," Schwartz said.
The proposed framework remains subject to community debate and has not been formalized as an active mainnet amendment.
On the XRP Ledger, any structural protocol adjustment requires a supermajority vote from network validators before deployment.
"If multiple validators did conspire, or a single validator attempted it, it would be very obvious to everyone exactly who was doing this," Schwartz said.
The executive noted that extracting meaningful value from sandwich attacks requires a rare combination of high and low liquidity, a state seldom observed on the network.
He added that no real-world front-running operations have been confirmed on the native exchange beyond proof-of-concept tests.