Ripple Director of Engineering Vijay Khanna urged XRP Ledger node operators on August 2 to upgrade to xrpld version 3.2.1 after developers spotted a validator manifest flood hitting the netwo
Ripple Director of Engineering Vijay Khanna urged XRP Ledger node operators on August 2 to upgrade to xrpld version 3.2.1 after developers spotted a validator manifest flood hitting the network on July 31. The release is an emergency hotfix and operators are advised to act promptly.
What Happened and Why It Matters
The flood centered on validator manifests, the cryptographically signed records that link a validator's permanent master identity to the temporary key it uses for day-to-day validation. When a validator rotates that temporary key, it broadcasts a new manifest so peers across the network can verify the change is legitimate.Nodes previously accepted, stored, and rebroadcast an unlimited number of manifests from unknown validator keys, creating a resource-exhaustion weakness that bad actors could exploit.
The XRP Ledger kept closing ledgers normally throughout the event, with no confirmed loss of funds, altered transactions, or consensus failure. However, the available evidence points to pressure on node resources and peer-to-peer communications.
What the Patch Does and How to Upgrade
Version 3.2.1 introduces four limits: a size cap that rejects any single manifest larger than expected; a receive cap that discards incoming batches over the limit rather than breaking the peer connection; a send cap that bounds the bulk manifest greeting sent to each new peer; and a cache cap that refuses new entries once 100 unknown keys are held.Manifests are also no longer persisted from unknown keys to disk, meaning a flood cannot survive a restart.
Node operators are urged to update normally to xrpld 3.2.1, wait one to two minutes and confirm xrpld is running, then restart xrpld a second time to clear any manifests that accumulated before the patch was applied. Administrators using packaged installations should also verify Ripple's current software-signing key, as Ripple rotated its GPG signing key in February 2026 and systems that have not trusted the replacement key may fail to receive automatic upgrades.
For ordinary $XRP holders, no action is required. The advisory is directed at infrastructure providers, exchanges, custodians, and data services that run their own ledger servers.The security update comes as the XRP Ledger prepares for another major software release, with Ripple's Head of Product Jasmine Cooper indicating that xrpld 3.3.0 is expected to be released in the near term pending validator approval.
Sources:XRP Ledger Urges Node Upgrade After Manifest Flood (Crypto.news)XRP Ledger Rolls Out Update to Fix Manifest Flood Vulnerability (The Crypto Times)XRP Ledger Releases 3.2.1 Hotfix to Stop Validator Manifest Flooding (Blockonomi)