XRP Ledger Stability Returns After July Manifest Flood Attack
David Schwartz, CTO Emeritus at Ripple and XRP Ledger co-architect, reports that XRPL hub metrics have returned to normal two weeks after July's disruptive manifest flood attack.
David Schwartz, CTO Emeritus at Ripple and one of the original architects of the XRP Ledger ($XRP), says his XRPL hub has remained stable for two weeks, offering the clearest signal yet that the network has recovered from July's damaging manifest flood attack.
Hub Metrics Back to Normal
Schwartz reported 406 active connections on his hub, in line with a recent average of 401. The hub reliably maintains around 400 simultaneous connections, peaking at 423, and latency fell to 165 milliseconds during the monitoring period. Median peer latency also remained near its recent average, and peer disconnections have declined. Abuse-related disconnects, a key indicator of residual attack activity, remain limited.
The telemetry covers the period from August 25 to September 8, and the hub is one of XRPL's key relay nodes through which other network nodes communicate. The only anomaly was a one-off latency spike on September 6, but the algorithms contained it without affecting consensus.
What Happened in July
In the evening of July 30, 2026, a flood of manifest messages propagated across the XRP Ledger's peer-to-peer network and overwhelmed the manifest-handling logic in xrpld, causing mass peer disconnects. Many nodes lost a majority of their peers within minutes, including two UNL nodes operated by Ripple and XRPSCAN.
Attackers flooded the network with large volumes of fake or unverified validator manifests. These cryptographic credentials allow validators to announce changes to their master keys or temporary signing keys. However, xrpld lacked sufficient resource limits for processing large volumes of untrusted manifests, and as nodes attempted to verify, track, and store the incoming data, pressure increased on CPU and memory resources.
The underlying ledger never halted or forked, and the remaining UNL validators maintained consensus throughout the flood. No loss of funds, private key compromise, or ledger data-integrity issue occurred.
Developers from the community swiftly responded, diagnosed the root cause, shipped an emergency mitigation to several nodes within a few hours, and released a standalone public hotfix (xrpld 3.2.1) by the evening of July 31. The 3.2.1 update introduced four protections: rejecting oversized validator manifests before full decoding, limiting incoming manifest batches a node can process at once, capping manifest data shared with newly connected peers, and preventing a node from storing manifests from more than 100 unknown validator keys.
Schwartz's latest hub data suggests those fixes are holding under real-world conditions, providing the XRP community with a data-backed confirmation that the network's peer layer has stabilised.
Sources:
XRPL.org: Vulnerability Disclosure Report, XRPL Manifest Flood (July 2026)
Crypto.news: XRP Ledger Urges Node Upgrade After Manifest Flood
The Crypto Times: XRP Ledger Rolls Out Update to Fix Manifest Flood Vulnerability
Latest News
Read More...
Author
Soumen DattaSoumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.













