In XRP news today, the XRP Ledger released xrpld 3.2.1 on July 31 after a validator manifest flood was detected hitting nodes that same day, with Ripple Director of Engineering Vijay Khanna issuing an urgent call on August 1–2 for all node operators to upgrade immediately.
The ledger continued closing normally throughout the incident, with no confirmed fund losses and no consensus failure, but unpatched nodes remain exposed to resource-exhaustion risk until operators complete the two-step upgrade process.
This news dropped as XRP USD fell 1.5% from $1.10 to $1.06 over the past 24 hours, with daily trading volume of $791M. This follows a worrying trend in which Ripple has crashed -4% over the past seven days.
XRP News: What the Manifest Flood Actually Did
The attack exploited a structural gap in how XRPL nodes handled validator manifests: before the patch, nodes would accept, cache, and rebroadcast an unlimited number of manifests tied to unknown validator keys with no ceiling on volume or storage.
An attacker could generate junk manifests at scale, forcing nodes to burn memory, disk space, and bandwidth processing data they would never act on.
The mechanism is closer to a denial-of-service resource drain than a consensus attack; the network’s transaction processing was never disrupted, but the exposure was real for any operator running unprotected infrastructure.
The development team confirmed the problem was specifically tied to how XRPLF nodes handled validator manifests, though as of publication the root cause and full exploitation details have not been publicly disclosed.
A technical post-mortem is forthcoming from XRPL Operations, which should clarify attacker behavior, traffic volumes, and any additional hardening steps.
For those tracking broader blockchain security vulnerabilities and attack vectors, the manifest flood fits a pattern where unbounded auxiliary data channels become leverage points even when consensus logic holds.
Discover: The Best Crypto to Diversify Your Portfolio
Four Safeguards Introduced in the Hotfix
The hotfix introduces four discrete protections targeting different points in the manifest handling pipeline. Oversized manifests are now rejected outright before full decoding. Incoming manifest batches per network message are capped.
The volume of manifest data shared with new peers is limited. And the unknown-key manifest cache is hard-capped at 100 entries, preventing unbounded growth from unrecognized validator identities.
Beyond those four caps, unknown validator manifests are no longer written to disk. That change means any pre-patch flood data is cleared on restart rather than persisting in storage, which is precisely why the upgrade requires a specific two-step sequence.
Firstly, install 3.2.1, let the server run for one to two minutes, then perform a second restart to purge any manifests retained from before the patch. Skipping the second restart leaves stale flood data in place. Operators should also verify their systems trust Ripple’s current GPG signing key, rotated February 18, 2026, or automatic upgrades may fail silently.
Trade XRP on Bybit and Get a Chance to Win Our $1,000 USDT Airdrop
Who Needs to Act and Why It Matters Now
In other XRP news, exchanges, custodians, wallet back ends, data providers, and any business running its own XRPL server must complete the node upgrade. Ordinary XRP holders do not need to move funds or change keys.
The urgency is compounded by upgrade adoption lag: xrpld v3.2.0, the larger June 15 release that renamed the reference server and required infrastructure config change, spread faster among validators than across the broader node network, meaning a cohort of operators may still be running older versions that are now doubly exposed.
The network security response here was operationally sound: a targeted hotfix, clear operator instructions, and a pending post-mortem that signals the team is treating this as a formal security incident rather than routine maintenance.
In the broader XRP ecosystem, the incident comes as the ledger scales; the network added nearly 490,000 new accounts in the first half of 2026, per supplementary data from Coinpaper, pushing total accounts past 8.4 million.
That growth trajectory makes robust infrastructure hardening a structural necessity, not an edge-case concern. Institutional developments, including Aviva’s tokenized liquidity fund on XRPL and growing enterprise adoption, raise the stakes for any operator still delaying the patch.
Discover: The Best Token Presales









