Ripple Director of Engineering Vijay Khanna has urged XRP Ledger node operators to install xrpld version 3.2.1 after a validator manifest flood was observed on July 31. The hotfix limits how nodes process, store and share data received from unknown validator identities. According to XRP Ledger Operations, the XRP Ledger continued closing ledgers normally during the event, with no confirmed loss of funds or failure of ledger consensus.
Upgrade Details
The upgrade is a response to a flaw in manifest propagation, which allowed an attacker to produce many unknown identities and force peers to spend memory, storage, bandwidth and processing capacity handling the data. The hotfix includes four commits that directly restrict untrusted manifest handling, including rejecting oversized validator manifests and limiting the number of untrusted manifests carried in one network message.
Impact and Response
The update applies to infrastructure providers rather than ordinary XRP holders, with exchanges, custodians, wallet back ends, data providers and businesses that run their own XRPL servers advised to confirm their node versions and restart status. A technical post-mortem is expected to follow soon, which will provide further details on the incident, including the identity of the sender and the volume of manifests transmitted.



