00:00
Money for You
Money for You
USD/RUB
EUR/RUB
Cryptocurrency

XRP Ledger issues emergency patch following validator manifest flood

Ripple’s engineering team has issued an urgent call for node operators to upgrade to xrpld version 3.2.1 after a July 31 incident saw an influx of malicious validator manifests. While the ledger’s consensus mechanism remained stable throughout the event, the flood threatened to overwhelm node memory and bandwidth resources.

XRP Ledger issues emergency patch following validator manifest flood

The flaw allowed attackers to inundate the network with cryptographically signed records that link validator master identities to temporary keys. By generating a high volume of unrecognized validator identities, the attack forced nodes to expend significant processing power and storage capacity to cache and broadcast the data. According to Vijay Khanna, Director of Engineering at Ripple, the new hotfix introduces four specific safeguards to neutralize the threat.

These controls now reject oversized manifests before decoding, cap the number of untrusted manifests per network message, and limit the node's unknown-key cache to 100 entries. These measures ensure that legitimate validator key rotations continue unimpeded while blocking the unchecked propagation of unverified data.

Infrastructure providers—including exchanges, custodians, and wallet backends—are instructed to perform a two-step restart process. Operators must first install the update and verify that the service is running, then trigger a second restart to purge any malicious manifests remaining in system memory. While the ledger continued to close normally during the flood, Ripple has promised a full post-mortem to determine the extent of the resource strain and the origin of the activity. Users holding XRP are unaffected by the incident and do not need to take any action regarding their personal assets.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!