XRP Ledger Calls for Urgent Node Update Following Manifest Flood
XRP Ledger Calls for Urgent Node Update Following Manifest Flood
On August 2, 2026, Ripple’s Director of Engineering, Vijay Khanna, urged operators of the XRP Ledger nodes to promptly update to version 3.2.1. This request follows the identification of a validator manifest flood incident that was first observed on July 31. Despite the flooding, the XRP Ledger continued to close ledgers without interruption.
Incident Details and Response
In response to the flooding, the update to xrpld version 3.2.1 includes several critical safeguards designed to cap the size of validator manifests, manage message batches, and control outbound sharing as well as growth of the unknown-key cache across the network. Operators are advised to upgrade and verify that xrpld is running correctly before performing a second restart to clear any persisted manifests safely.
The hotfix introduces limitations on how nodes process and store data from unknown validator identities, aiming to prevent resource exhaustion. Throughout the incident, there was no confirmed loss of funds, alteration of transactions, or failure of ledger consensus, indicating that the issue primarily placed pressure on node resources and peer-to-peer communications.
Understanding the Manifest Flood
Validator manifests serve as cryptographically signed records linking a validator’s master identity to temporary keys used for daily validation messages. The update responds to vulnerabilities that allowed nodes to accept and cache manifests from unrecognized validator keys, potentially facilitating an attack that could overwhelm a node’s resources.
The new version limits the number of untrusted manifests that can be processed in one network message and sets constraints on the number of unknown validator identities that a node can cache. When the cache reaches its limit, manifests tied to new unrecognized keys are rejected, allowing nodes to maintain functionality with known validators.
Instructions for Node Operators
Khanna emphasized the need for all validators and infrastructure operators to upgrade to version 3.2.1 as soon as possible. The process requires a standard software upgrade, followed by a brief wait to verify that xrpld is operational, and then a second service restart to ensure old data does not continue to impact operations. Operators must also confirm that their systems trust Ripple’s updated package-signing key, as this change was instituted earlier in February.
Looking Ahead
A post-mortem report detailing the incident’s scope is expected soon from XRP Ledger Operations. While they have yet to disclose information about the volume of manifests transmitted or the specific impacts on nodes, the report will likely provide insights into when the issue was first detected and the response time of operators to implement the update.
As XRP Ledger continues to evolve with updates like version 3.2.1, operators are encouraged to keep their systems updated to mitigate potential vulnerabilities and ensure stable operations.
Source: crypto.news