XRP Update: xrpld 3.2.1 Hotfix Severs Manifest Flood Eroding XRPL Node Resources

On July 31, the XRP Ledger rolled out xrpld 3.2.1 following detection of a validator manifest flood that struck nodes that day, prompting Ripple’s Director of Engineering Vijay Khanna to urge all node operators to upgrade at once on August 1–2.
Throughout the incident, the ledger continued to close transactions normally, with no confirmed fund losses or consensus failures, yet nodes that have not applied the patch remain vulnerable to resource exhaustion until the two‑step upgrade is finished.
The announcement coincided with a 1.5% drop in XRP USD from $1.10 to $1.06 in the last 24 hours, against a daily trading volume of $791M, adding to a worrying -4% decline over the past week.
XRP Update: The Real Impact of the Manifest Flood
The exploit targeted a structural flaw in XRPL node handling of validator manifests: prior to the patch, nodes would accept, cache, and rebroadcast an unlimited number of manifests linked to unknown validator keys, with no cap on volume or storage.
Attackers could flood the network with spurious manifests at scale, forcing nodes to consume memory, disk space, and bandwidth on data that would never be acted upon.
The mechanism resembles a denial‑of‑service resource drain more than a consensus attack; transaction processing remained unaffected, yet operators with unpatched infrastructure faced genuine risk.
The development team confirmed the issue was specifically linked to XRPLF nodes’ handling of validator manifests, though the root cause and complete exploitation details remain undisclosed as of now.

XRPL Operations will release a technical post‑mortem to clarify attacker tactics, traffic volumes, and additional hardening measures.
For blockchain security observers, the manifest flood exemplifies how unbounded auxiliary data channels can become attack vectors even when consensus logic remains intact.
Four Protective Measures Added in the Hotfix
The hotfix implements four distinct safeguards at various stages of the manifest processing pipeline. Oversized manifests are immediately rejected before decoding. Each network message’s incoming manifest batch size is capped. The amount of manifest data exchanged with new peers is restricted. The cache for unknown‑key manifests is hard‑capped at 100 entries, preventing unchecked growth from unidentified validator identities.
In addition, unknown validator manifests are no longer persisted to disk. This ensures that any pre‑patch flood data is purged upon restart, which explains why the upgrade mandates a precise two‑step process.
First, install 3.2.1 and allow the server to run for one to two minutes, then perform a second restart to clear any pre‑patch manifests. Skipping the second restart will leave stale flood data on the node. Operators should also confirm that their systems trust Ripple’s current GPG signing key, rotated February 18, 2026, as automatic upgrades could fail silently otherwise.
Trade XRP on Bybit and Enter to Win a $1,000 USDT Airdrop
Who Must Act and Why It Matters Now
Other XRP news: exchanges, custodians, wallet back‑ends, data providers, and any entity operating its own XRPL server must complete the node upgrade. Regular XRP holders need not move funds or change keys.
The urgency is amplified by adoption lag: xrpld v3.2.0, the June 15 release that renamed the reference server and required infrastructure changes, spread more quickly among validators than across the wider node network, leaving some operators still on older versions now doubly vulnerable.
The network security response was operationally solid: a targeted hotfix, explicit operator guidance, and an upcoming post‑mortem indicate the team treats this as a formal security incident, not routine maintenance.
Within the broader XRP ecosystem, the incident occurs amid ledger scaling; the network added nearly 490,000 new accounts in the first half of 2026, per supplementary data from Coinpaper, pushing total accounts beyond 8.4 million.
This growth trajectory makes robust infrastructure hardening a structural necessity rather than a niche concern. Institutional initiatives, such as Aviva’s tokenized liquidity fund on XRPL and increasing enterprise adoption, heighten the stakes for operators still delaying the patch.