In today’s XRP news, the XRP Ledger launched the xrpld 3.2.1 hotfix on July 31 after detecting a validator manifest flooding issue affecting network nodes. Ripple Director of Engineering Vijay Khanna later called on all XRPL node operators on Aug. 1–2 to upgrade their systems without delay.
The incident did not disrupt ledger operations, with transactions continuing to finalize normally and no confirmed losses of funds or consensus failures reported. However, nodes that remain unpatched continue to face possible resource exhaustion risks until the complete upgrade process is completed.
The update arrived as XRP dropped 1.5% over the last 24 hours, moving from $1.10 to $1.06, with daily trading volume reaching around $791 million. The decline follows broader weakness, with XRP losing approximately 4% over the past week.
Understanding the XRPL Validator Manifest Flood
The vulnerability was linked to the way XRPL nodes managed validator manifests. Before the hotfix, nodes could accept and relay an unlimited number of manifests associated with unknown validator keys, without any restrictions on storage usage or incoming volume.
Attackers could exploit this weakness by generating large amounts of unnecessary manifest data, forcing nodes to dedicate memory, disk capacity, and bandwidth toward processing information that did not provide any network benefit.
The issue was considered a denial-of-service style resource attack rather than an attack on XRPL consensus. The ledger’s ability to validate transactions and maintain agreement across nodes remained intact, but vulnerable infrastructure could experience performance problems.
XRPL engineers confirmed that the weakness affected validator manifest processing within XRPLF nodes. However, the development team has not yet released full details regarding the attack method, the volume of malicious traffic, or the exact scope of exploitation.
XRPL Operations is expected to release a technical post-mortem outlining the incident, attacker behavior, and any further improvements planned for network resilience.
The event highlights a recurring challenge across blockchain systems: even non-consensus components can become attack surfaces when supporting data processes lack proper limitations.
Security Updates Included in xrpld 3.2.1
The xrpld 3.2.1 release introduces four major protections designed to prevent future validator manifest abuse.
The update blocks oversized manifests before they undergo complete decoding, restricts the number of manifests accepted within individual network messages, limits manifest data shared with newly connected peers, and caps the cache for unknown validator-key manifests at 100 entries.
The patch also prevents unknown validator manifests from being stored permanently on disk. This ensures that any malicious manifest information collected before the upgrade is removed after restarting the server.
Due to this change, node operators must follow a two-step upgrade process.
First, operators should install xrpld 3.2.1 and allow the node to remain active for one to two minutes. A second restart is then required to remove any older manifest data that may have been retained before the patch was installed.
Failing to complete the second restart could leave outdated flood-related information on the system and prevent the upgrade from fully resolving the issue.
Operators should also verify that their installations recognize Ripple’s current GPG signing key, which was rotated on Feb. 18, 2026. Systems using outdated keys may experience silent failures during automated upgrade attempts.





