The XRP Ledger is kept running by independent servers called validators, run by universities, exchanges, businesses, and individuals around the world. There are more than 150 of them, and most servers trust a shorter default list of about 35 (source: XRP Ledger, FAQ). Ripple, the company most associated with XRP, runs only one validator on that default list.
That last fact is the heart of the decentralization question, so it is worth being precise about who validates the ledger, how they are chosen, and how much control any single party, Ripple included, really has. This guide answers the "who and how decentralized" question. The mechanics of how those validators reach agreement are covered separately in the XRP Ledger consensus protocol, and the wider settlement picture in the parent guide, how the XRP Ledger works.
What a validator actually does
A validator is a server that issues signed validation votes on each proposed ledger, on top of relaying transactions and storing the full ledger. Anyone can run one. Running a validator does not by itself give you a say; other servers ignore your votes unless they choose to trust you (source: XRP Ledger, run a validator).
That last point is what stops the validator role from being a popularity contest of raw numbers. Influence is granted, not taken. A server only counts votes from validators on its own trusted list, so spinning up a hundred new validators changes nothing unless real operators decide to add them.
Even validators that nobody lists still serve a purpose. They act as a benchmark: if a trusted validator starts disagreeing with the broad field of unlisted ones, that is an early signal its software is outdated, buggy, or misconfigured. In effect the wider validator pool quietly measures the trusted few, without ever being counted in a single consensus round.
Good validators share a few traits that make operators willing to trust them: near-constant uptime, votes that consistently match the network's outcome, prompt responses, and a clearly identified owner. That last trait matters for decentralization. Reputable validators publish domain verification so anyone can confirm who runs them, and the healthiest trusted lists deliberately spread across different owners, legal jurisdictions, and regions, so no single local event can knock out a big share of them at once.
Who runs the validators
The validators are operated by a genuinely mixed group: universities, cryptocurrency exchanges, payment businesses, infrastructure providers, and independent community members, spread across many countries (source: XRP Ledger, about). One of the long-running validators, for instance, is operated out of a university. This spread is not decorative; it is the mechanism that keeps control from pooling in one place.
There is no block reward for any of this. Validators are not paid in new XRP for taking part, so the people running them are doing so because a reliable, neutral network is worth more to them than a subsidy would be. That volunteer economics is unusual, and it shapes who bothers to run a validator: mostly organizations with a direct stake in the ledger staying healthy.
The default list, and why you can ignore it
Most server operators do not hand-pick validators one by one. They trust a default Unique Node List, or dUNL: a curated set of roughly 35 well-run validators published by the XRP Ledger Foundation and by Ripple. The other 150-plus validators on the network are not on that default list, though any operator can add them.
The word "default" is doing important work. The list is a recommendation, not a rule. Any operator is free to edit it, drop validators, add others, or follow a completely different publisher's list. The only practical constraint is overlap: if your chosen list differs too much from everyone else's, your server can fall out of step with the network. So operators tend to converge on similar lists by choice, not because anyone forces the choice on them.
How decentralized is it, really
This is where honest framing matters. The case for concern is real and worth stating plainly: Ripple created the XRP Ledger, still holds a large amount of XRP in on-ledger escrow, and is one of only two publishers of the default validator list. Those are genuine points of influence.
The counterweights are just as concrete. Ripple runs only one of the roughly 35 validators on the default list, and its rights on the network are the same as any other contributor. It uses the ledger to build its own products but does not own, maintain, or develop the ledger itself (source: Investopedia, Ripple and XRP). It cannot freeze the XRP in your account, change the supply, or force a rule change on its own. And because every operator opts in to its own trusted list, the community could route around Ripple entirely by switching to a different publisher if it ever stopped operating or acted against the network's interest.
It also helps that Ripple's biggest lever, its XRP holdings, sits in public on-ledger escrow rather than in a private wallet, so the market can see exactly how much could enter circulation and when. Transparency does not remove the concentration, but it removes the surprise, which is part of why the escrow was structured that way.
The direction of travel matters too. In the earliest days Ripple ran effectively all of the trusted validators; today it runs one of dozens. Decentralization here is a spectrum, not a switch, and the ledger sits further along it than the "Ripple's coin" shorthand suggests, without being as trustless as a large proof-of-work network. Reasonable people weigh those facts differently, and that is the honest state of the debate.
Who decides what changes on the ledger
No company and no token-holder vote decides changes to the XRP Ledger. New features arrive as amendments, and an amendment only activates if a supermajority of trusted validators supports it continuously over a sustained period (source: XRP Ledger, amendments). This is a very different governance model from a company pushing an update to its own app.
In concrete terms, an amendment needs more than 80 percent of the default validators, 28 of the 35, to hold their support for two straight weeks before it goes live, and dropping below that bar even briefly resets the clock (source: 24/7 Wall St, XRP Ledger amendment vote). Simply installing new software is not the same as voting yes; a validator can run the update and still vote against the change. There is no deadline, so some proposals pass in weeks, some drag on for months, and some never pass at all.
For an everyday XRP holder, the takeaway is simple. The rules of the network you rely on cannot be changed quietly by one party overnight. They change slowly, in the open, and only with broad validator agreement sustained over time. That is far slower than a company shipping an app update, but it is exactly the property that lets independent businesses build on the ledger without fearing the ground will shift under them.
Staying live when validators drop out
Because the network needs about 80 percent agreement to finalize a ledger, it is sensitive to validators going offline. A feature called the Negative UNL handles this: when trusted validators appear down, a consensus of the rest can temporarily set them aside so the network still reaches quorum among those online (source: XRP Ledger, Negative UNL).
The mechanism is measured, not instant. A validator is only set aside after its recent votes fall out of line with the network over a stretch of ledgers, and it is added back automatically once it is reliably in sync again, so a brief hiccup does not permanently drop anyone.
There is a hard floor built in. The Negative UNL can never reduce the requirement below 60 percent of the total list, which stops the network from fragmenting into rival groups during an outage. And if too many validators vanish at once rather than one at a time, the ledger pauses rather than pushing ahead, the same correctness-first choice that runs through the whole consensus design. Resilience here means degrading safely, not pretending nothing is wrong.
Frequently asked questions
Does Ripple control the XRP Ledger?
No. Ripple runs only one of the roughly 35 validators on the default trusted list, and its rights on the network are the same as any other operator. It cannot freeze your XRP, change the supply, or force through a rule change alone. Because trusted lists are opt-in, participants can switch away from Ripple's list at any time.
Would the XRP Ledger keep running if Ripple disappeared?
Yes. The great majority of validators are run by other parties, and no single operator is required for consensus. If Ripple stopped operating, servers could simply trust a validator list from a different publisher, such as the XRP Ledger Foundation, and the network would continue to reach agreement and settle transactions.
How many validators would an attacker need to control?
To force an invalid transaction through, an attacker would need more than 80 percent of a server's trusted validators to collude in the same fraud. Running many new validators does not help, because servers only count votes from validators they have chosen to trust, which defeats a Sybil attack by design.
Researched and written for the BloFin Academy. This article is educational and is not financial, investment, or legal advice. Always do your own research.
