Particle.news
Download on the App Store

XRP Ledger Issues xrpld 3.2.1 Hotfix After Validator-Manifest Flood

The update adds four limits to stop untrusted validator manifests from exhausting node memory, bandwidth and storage, and operators must upgrade then perform a required second restart.

Overview

  • A validator-manifest flood on Friday, July 31 overloaded parts of the XRPL peer-to-peer layer by allowing many valid-looking manifests tied to unknown keys to be accepted, cached and rebroadcast across nodes.
  • Developers published xrpld version 3.2.1 as a stability hotfix and have urged node operators to install the release, confirm xrpld is running briefly, then restart the service a second time to clear persisted unknown manifests.
  • The hotfix implements four safeguards: reject oversized manifests before decoding, cap untrusted manifests per message, limit manifest greeting/broadcasts on new peer connections, and cap the unknown-key manifest cache at 100 entries.
  • Available evidence shows ledgers continued closing and consensus stayed intact during the event, but developers have not published a CVE identifier or any financial-loss estimate and a technical post-mortem has not yet been released.
  • Operators who use packaged installs should verify they trust Ripple’s rotated GPG signing key from February 2026 or they may miss automatic updates, and slow patch adoption could leave exchanges, custodians and independent nodes exposed to renewed probing or resource strain.