(Advertisement)

top ad mobile advertisement
news13d ago

Ripple Urges XRP Ledger Nodes To Install Critical Security Fix

Ripple Director of Engineering Vijay Khanna has urged XRP Ledger node operators to upgrade to xrpld version 3.2.1, a hotfix that blocks the manifest flood attack observed on July 31.

Ripple Urges XRP Ledger Nodes To Install Critical Security Fix

(Advertisement)

native ad1 mobile advertisement

Ripple Director of Engineering Vijay Khanna urged XRP Ledger node operators on August 2 to upgrade to xrpld version 3.2.1 after developers spotted a validator manifest flood hitting the network on July 31. The release is an emergency hotfix and operators are advised to act promptly.

What Happened and Why It Matters

The flood centered on validator manifests, the cryptographically signed records that link a validator's permanent master identity to the temporary key it uses for day-to-day validation. When a validator rotates that temporary key, it broadcasts a new manifest so peers across the network can verify the change is legitimate. Nodes previously accepted, stored, and rebroadcast an unlimited number of manifests from unknown validator keys, creating a resource-exhaustion weakness that bad actors could exploit.

The XRP Ledger kept closing ledgers normally throughout the event, with no confirmed loss of funds, altered transactions, or consensus failure. However, the available evidence points to pressure on node resources and peer-to-peer communications.

What the Patch Does and How to Upgrade

Version 3.2.1 introduces four limits: a size cap that rejects any single manifest larger than expected; a receive cap that discards incoming batches over the limit rather than breaking the peer connection; a send cap that bounds the bulk manifest greeting sent to each new peer; and a cache cap that refuses new entries once 100 unknown keys are held. Manifests are also no longer persisted from unknown keys to disk, meaning a flood cannot survive a restart.

Node operators are urged to update normally to xrpld 3.2.1, wait one to two minutes and confirm xrpld is running, then restart xrpld a second time to clear any manifests that accumulated before the patch was applied. Administrators using packaged installations should also verify Ripple's current software-signing key, as Ripple rotated its GPG signing key in February 2026 and systems that have not trusted the replacement key may fail to receive automatic upgrades.

For ordinary $XRP holders, no action is required. The advisory is directed at infrastructure providers, exchanges, custodians, and data services that run their own ledger servers. The security update comes as the XRP Ledger prepares for another major software release, with Ripple's Head of Product Jasmine Cooper indicating that xrpld 3.3.0 is expected to be released in the near term pending validator approval.

Sources:
XRP Ledger Urges Node Upgrade After Manifest Flood (Crypto.news)
XRP Ledger Rolls Out Update to Fix Manifest Flood Vulnerability (The Crypto Times)
XRP Ledger Releases 3.2.1 Hotfix to Stop Validator Manifest Flooding (Blockonomi)

Latest News

Read More...

Author

Soumen Datta profile photoSoumen Datta

Soumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.

Join our newsletter

Sign up for the very best tutorials and the latest Web3 news.

Subscribe Here!
BSCN

BSCN

BSCN RSS Feed

BSCN is your destination for all things crypto and blockchain. Discover the latest cryptocurrency news, market analysis, and research covering Bitcoin, Ethereum, altcoins, memecoins and everything in between.