XRP Ledger Releases Critical Hotfix to Prevent Resource-Exhausting Attack
A critical hotfix has been released for XRP Ledger's xrpld software to address a manifest flood attack that drained node resources.
The attack, which exploited a structural gap in how XRPL nodes handled validator manifests, caused nodes to burn memory, disk space, and bandwidth processing data they would never act on.
Ripple Director of Engineering Vijay Khanna issued an urgent call for all node operators to upgrade immediately to xrpld version 3.2.1, which includes a hotfix designed to prevent the manifest flood attack observed on the network.
The hotfix introduces four discrete protections targeting different points in the manifest handling pipeline, including capping incoming manifest batches per network message and limiting the volume of manifest data shared with new peers.