BNB $587.13 +0.83%
XRP $1.07 -0.50%
ETH $1,857.16 +0.20%
BTC $63,280.43 +0.35%
BNB $587.13 +0.83%
XRP $1.07 -0.50%
ETH $1,857.16 +0.20%
BTC $63,280.43 +0.35%
BREAKING
Altcoins News

XRP Ledger Hotfix Patches Manifest Flood That Threatened 8.4 Million Accounts

XRP Ledger Hotfix Patches Manifest Flood That Threatened 8.4 Million Accounts
XRP Ledger Hotfix Patches Manifest Flood That Threatened 8.4 Million Accounts

Community Trust ScoreVerified

91%
Real
Verified23 votes
Updated 2 hours ago

XRP Ledger pushed a hotfix on July 31. The update, xrpld 3.2.1, came after the network’s nodes took a hit from a manifest flood attack — the kind of low-noise, resource-draining assault that doesn’t steal funds but can quietly cripple infrastructure if nobody catches it fast enough.

Ripple’s Director of Engineering, Vijay Khanna, called on node operators to upgrade immediately, with the push happening over August 1 and 2. No funds were lost. Network consensus stayed intact. But unpatched nodes remain exposed until operators complete a specific two-step upgrade process — and that’s not a small caveat.

How the Manifest Flood Actually Worked

The attack hit a gap in how XRPL nodes handled validator manifests. Before the patch, nodes would accept, cache, and rebroadcast manifests tied to unknown validator keys — with zero volume limits. No ceiling. Attackers could pour junk manifests into the network and watch nodes burn through memory, disk space, and bandwidth processing data that meant nothing.

Advertisement

Transaction processing itself wasn’t touched. The ledger kept moving. But the infrastructure underneath? Quietly getting eaten alive by garbage data. The development team pinpointed the problem in the manifest handling logic, though the full exploitation details haven’t been made public yet. Probably wise — no need to hand anyone a roadmap.

The 3.2.1 hotfix drops four specific protections into the manifest pipeline. Oversized manifests get rejected before decoding even starts. Manifest batches per network message are now capped. The amount of shared manifest data sent to new peers is limited. And the cache for unknown-key manifests is hard-capped at 100 entries. On top of that, unknown validator manifests are no longer written to disk at all.

The Two-Step Upgrade Operators Can’t Skip

Installing the update isn’t a one-click fix. Operators need to install version 3.2.1, let the server run for a few minutes, then do a second restart to flush out any pre-patch data still sitting on the system. Skip that second step and residual manifest data from the flood could still be lurking. Unclear exactly how many operators have completed the full process so far, but the urgency is real.

There’s another wrinkle. Operators need to make sure their systems trust Ripple’s current GPG signing key — the one updated on February 18, 2026. If that key isn’t current, the upgrade can fail silently. No error message, no warning, just a system that thinks it’s patched but isn’t. That’s the kind of thing that keeps infrastructure teams up at night.

The slow uptake on xrpld v3.2.0, released back on June 15, made this worse. A lot of operators hadn’t even moved to that version yet when the flood hit. So the gap between the network’s current state and where it needs to be is wider than it should be.

Exchanges, custodians, wallet back ends, data providers, businesses running their own XRPL servers — all of them need to act. Regular XRP holders don’t need to do anything. But the people running the pipes? They’re on the clock.

Why the Stakes Are Higher Now

XRPL added over 490,000 new accounts in the first half of 2026 alone. Total accounts on the network have passed 8.4 million. That’s not a niche ledger anymore — it’s a network carrying serious institutional weight, including initiatives like Aviva’s tokenized liquidity fund. More users, more transactions, more reasons for bad actors to probe for weaknesses.

And that’s kind of the core tension here. Blockchain consensus mechanisms can be rock solid while the supporting infrastructure — the manifest handling, the peer data sharing, the caching logic — gets exploited through a side door. It’s basically a denial-of-service angle. Not glamorous, not the stuff of headline hacks, but effective enough to degrade node performance and rattle operators who aren’t watching closely.

The development team has said a technical post-mortem is coming. That’ll probably give a clearer picture of how the attack unfolded and what additional defenses might follow. For now, the hotfix is the answer, and the ask is simple: upgrade, restart twice, check the GPG key.

Node operators who haven’t moved to 3.2.1 are still running exposed infrastructure on a network that just crossed 8.4 million accounts.

Frequently Asked Questions

What did the xrpld 3.2.1 hotfix fix on the XRP Ledger?

The update patched a manifest flood vulnerability where XRPL nodes accepted and cached unlimited validator manifests from unknown keys, draining memory, disk space, and bandwidth. Four new protections were added, including a 100-entry cap on unknown-key manifest caches and rejection of oversized manifests before decoding.

Who needs to upgrade after the XRP Ledger manifest flood attack?

Exchanges, custodians, wallet back ends, data providers, and any business running an XRPL server must complete the two-step upgrade to xrpld 3.2.1. Ordinary XRP holders don’t need to take any action.

Community Trust IndexHigh Confidence
91%
Real
Real91%9%Fake
23 community signals

Jean-Luc Maracon

Jean-Luc Maracon is a French-Swiss expert in decentralized finance, known for his sharp analysis of Bitcoin, European Web3 projects, and crypto regulatory challenges. Splitting his time between Geneva and Paris, he brings a unique perspective blending traditional finance with blockchain innovation. He regularly collaborates with crypto platforms across Europe to help make digital investing more accessible. Specialties: Bitcoin, staking, European regulation, crypto security, Web3.

Advertisement

Related Stories