Ripple's Director of Engineering, Vijay Khanna, announced that the latest XRP Ledger update, version 3.2.1, is key for node operators to install immediately. This patch addresses a serious vulnerability exposed last Friday, July 31, when the network experienced a manifest flood attack that threatened its stability.

The Manifest Flood Vulnerability and Its Impact

The manifest flood attack exploited the way XRPL nodes handle validator manifests. Previously, nodes accepted, stored, and rebroadcast an unlimited number of manifests from unknown validator keys. This created an opportunity for attackers to overwhelm the network with excessive manifest data, potentially degrading node performance or causing disruptions. The flood was a significant risk, especially as the network continues to support critical financial applications and digital assets.

How Version 3.2.1 Secures the Network

Ripple's hotfix introduces strict limits to prevent such floods. These include capping the size of individual manifests, discarding batches that exceed a set threshold without breaking peer connections, limiting bulk manifest greetings to new peers, and refusing new unknown keys once 100 are cached. also manifests from unknown keys are no longer saved to disk, ensuring that a flood cannot persist through node restarts. The update aims to safeguard the network’s integrity and maintain smooth operation for all participants.

Node operators must upgrade to XRPL 3.2.1 promptly using normal update procedures to avoid vulnerabilities. This call to action follows the recent warning about a Ripple announcement scam that highlighted the importance of security awareness across the ecosystem.

This material is for informational purposes only and does not constitute financial advice.