XRPL Patches Resource Drain; XRP Still Bleeds 1.5% While Nodes Play Catch-Up 🩹
The XRP Ledger released xrpld 3.2.1 on July 31 after a validator manifest flood was detected hitting nodes that same day, prompting Ripple Director of Engineering Vijay Khanna to issue an urgent call on August 1–2 for all node operators to upgrade immediately. The ledger continued closing normally throughout the incident, with no confirmed fund losses and no consensus failure, but unpatched nodes remain exposed to resource-exhaustion risk until operators complete the two-step upgrade process. As of reporting, $XRP was down 1.5% from $1.10 to $1.06 over the past 24 hours on daily trading volume of $791M, extending a seven-day slide in which Ripple has lost 4%.
The attack exploited a structural gap in how XRPL nodes handled validator manifests: before the patch, nodes would accept, cache, and rebroadcast an unlimited number of manifests tied to unknown validator keys with no ceiling on volume or storage. An attacker could generate junk manifests at scale, forcing nodes to burn memory, disk space, and bandwidth processing data they would never act on. The mechanism is closer to a denial-of-service resource drain than a consensus attack; the network's ledger continued to close and validate transactions normally even while individual nodes were being overloaded.
Khanna's public message, posted to X on August 1, read: "XRPL Node operators, Please upgrade to 3.2.1 asap. It has a hotfix that prevents the manifest flood attack," linking operators to the official release. The fix caps the number of manifests a node will retain for unknown validators, preventing the unbounded queue that made the flood possible in the first place.
Operators running the previous 3.2.0 release are required to apply the hotfix in two steps to maintain sync with the rest of the network, and any node still on older software is expected to fall behind as peers drop connections to non-upgraded participants. Ripple engineers have not publicly attributed the flood to a specific actor, and no on-chain transactions or balances were reported as affected by the incident.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.