XRP Ledger Releases Hotfix for Manifest Flood Attack
XRP Ledger recently released a hotfix for xrpld version 3.2.1 to address a manifest flood attack that occurred on July 31.
The attack exploited a structural gap in how XRPL nodes handled validator manifests, allowing an attacker to generate junk manifests at scale and force nodes to burn memory, disk space, and bandwidth processing data they would never act on.
Ripple Director of Engineering Vijay Khanna issued an urgent call for all node operators to upgrade immediately, which was followed by the release of the hotfix.
The hotfix introduces four discrete protections targeting different points in the manifest handling pipeline, including capping oversized manifests and incoming manifest batches per network message.