In the latest XRP news, the XRP Ledger released the xrpld 3.2.1 hotfix on July 31 after detecting a validator manifest flood affecting network nodes. Ripple Director of Engineering Vijay Khanna later urged all node operators on Aug. 1–2 to upgrade to the latest version as quickly as possible.
The XRPL network continued processing transactions normally throughout the incident, with no reported loss of funds or consensus disruption. However, nodes that have not installed the update remain vulnerable to potential resource exhaustion until operators complete the required two-stage upgrade process.
The update came as XRP traded lower, falling 1.5% from $1.10 to $1.06 over the previous 24 hours, with daily trading volume reaching $791 million. The move added to recent weakness, with XRP down around 4% over the past week.
What Happened During the XRPL Manifest Flood
The issue exploited a weakness in how XRPL nodes processed validator manifests. Before the fix was deployed, nodes could accept, store, and redistribute unlimited numbers of manifests connected to unknown validator keys, without restrictions on volume or storage capacity.
An attacker could take advantage of this by creating large amounts of invalid or unnecessary manifest data, forcing nodes to consume additional memory, disk space, and network bandwidth while handling information they would never use.
The attack functioned more like a denial-of-service resource exhaustion attempt rather than a threat to network consensus. Transaction processing remained unaffected, but node operators running outdated software faced increased infrastructure risks.
XRPL developers confirmed that the vulnerability was related to validator manifest processing within XRPLF nodes. However, the complete technical details and the exact method used by the attacker have not yet been publicly revealed.
XRPL Operations is expected to publish a detailed post-mortem explaining the attack pattern, traffic levels, and any additional security improvements introduced after the incident.
The vulnerability highlights a broader blockchain security challenge: even when consensus mechanisms remain secure, unrestricted supporting data systems can become potential targets for resource-based attacks.
Four Security Improvements Added in xrpld 3.2.1
The xrpld 3.2.1 hotfix introduces four major safeguards designed to limit abuse of the validator manifest system.
The update now blocks oversized manifests before they are fully processed, restricts the number of incoming manifests allowed in each network message, limits the amount of manifest data shared with new peers, and places a maximum limit of 100 entries on the cache for unknown validator-key manifests.
In addition to these protections, manifests linked to unknown validators are no longer stored on disk. This ensures that any malicious manifest data collected before the upgrade is removed after a restart instead of remaining persistent.
Because of this change, operators must follow a specific two-step upgrade process.
First, node operators should install version 3.2.1 and allow the server to run for one to two minutes. After that, they must restart the server a second time to remove any previously stored manifest data created before the patch.
Failing to complete the second restart could leave outdated flood-related data on the system.
Operators should also confirm that their installations recognize Ripple’s updated GPG signing key, which was rotated on Feb. 18, 2026. Without the correct key, automated upgrade processes may fail without an obvious warning.

More Stories
Strategy Trims Bitcoin Holdings by $105M While Boosting STRC Share Repurchases
Bitcoin and Ether Slide as Coldcard Wallet Exploit Extends Into Fifth Day
Bitcoin Futures Premium Crashes as Yields Sink Below U.S. Treasury Returns