Key Highlights
- XRP Ledger released version 3.2.1 to fix a manifest flood vulnerability without disrupting network operations.
- The update adds four new protections to prevent unknown validator manifests from overwhelming XRPL nodes.
- XRPL is preparing for the upcoming 3.3.0 upgrade, which is expected to introduce new features for tokenized assets, pending validator approval.
The XRP Ledger (XRPL) has rolled out a major software update after developers discovered a security issue that affected some of the network’s nodes on July 31.
In a Saturday post on X, XRPL Operations confirmed that the update is now live, fixing the issue and adding safeguards to prevent similar incidents, even though the network continued operating normally throughout the event.
“XRP Ledger 3.2.1 is now available. This fixes the manifest flood observed on Friday, July 31. The XRPL continued closing ledgers normally throughout. A post-mortem will follow soon for the community,” XRPL Operations posted on X.
What triggered the XRPL manifest flood?
The issue was described as a manifest flood. According to the developers, the problem was connected to the way XRPL nodes handled validator manifests from unknown validator keys. Validator manifests help the network identify and manage trusted validators.
Before the update, nodes accepted, stored, and shared an unlimited number of manifests from unknown validator keys. While this did not stop the blockchain from working, it allowed a large amount of unnecessary data to build up, using extra resources on affected nodes.
As soon as the issue was discovered, the development team began working on a fix. While they have not yet revealed what caused the problem, they said they will publish a detailed post-mortem report for the community in the future.
Their immediate focus was to release an update that would protect the network and reduce the chances of the same type of attack happening again.
What’s new in the XRPL 3.2.1 update
The XRPL 3.2.1 update introduces four important protections. First, the software now rejects any validator manifest that is much larger than expected.
Second, it limits the number of incoming batches of manifests that a node can process at one time. Third, it places a limit on the amount of manifest data shared with newly connected peers.
Finally, it prevents a node from storing manifests from more than 100 unknown validator keys. These changes are designed to reduce unnecessary data and stop unknown validator information from overwhelming the system.
Developers also made another important improvement. In earlier versions, manifests from unknown validator keys could be saved to a node’s storage. With the latest update, those manifests are no longer written to disk. This means that if unwanted data floods a node, it will be cleared after the node is restarted instead of staying in the system.
The team also asked node operators to update as soon as possible. They advised users to install XRPL 3.2.1, wait one to two minutes to make sure xrpld is running, and then restart the software again. According to the developers, this final restart is an important part of completing the update correctly.
What’s next for the XRP Ledger?
The security update comes as the XRP Ledger prepares for another major software release. Ripple’s Head of Product, Jasmine Cooper, recently said xrpld 3.3.0 is expected to be released next week if network validators approve it.
Unlike version 3.2.1, which focuses on fixing a security issue, the upcoming release is aimed at adding new features that make the blockchain more useful for businesses and financial institutions working with tokenized assets.
Cooper said, “XRPL has already proven it can support tokenized assets at scale. Now it’s time to put these assets to use: global transfers, trading, collateralizing, and settling.”
Also Read: Wanchain Sets August 6 Deadline for Cardano Bridge Hacker
