Back to top
  • 공유 Share
  • 인쇄 Print
  • 글자크기 Font size
URL copied.

XRP Ledger Abuse Drops Near Zero After July Attack

XRP Ledger Abuse Drops Near Zero After July Attack. Source: EconoTimes

XRP Ledger (XRPL) infrastructure has returned to stable operating conditions following July’s network-wide manifest flood attack, according to new metrics shared by Ripple CTO Emeritus and XRPL architect David Schwartz.

Schwartz published telemetry from his private XRPL hub covering August 25 through September 8, describing its performance as “Rock Solid.” The hub is an important relay server that connects with other nodes across the XRP Ledger network.

The update follows the July 31 incident, when attackers launched a “manifest storm” by flooding XRPL nodes with thousands of fraudulent validator credentials. Manifests are digital credentials used by validator nodes, and the attack forced network infrastructure to devote resources to processing large volumes of unwanted data.

Schwartz’s hub experienced widespread connection failures during the incident, including onReadMessage errors while nodes were comparing ledger states. Despite the disruption, XRPL consensus and ledger finalization continued without interruption.

Developers responded by releasing the xrpld 3.2.1 hotfix, which imposed limits on manifest sizes and changed how data from unknown nodes is cached. The measures were designed to prevent suspicious participants from consuming excessive network resources.

More than a month later, Schwartz’s latest data indicates that the changes are working under real-world conditions. His private XRPL hub maintained roughly 400 simultaneous connections, reaching a peak of 423. That included 135 inbound and 271 outbound connections.

Peer latency fell to around 165 milliseconds. A brief spike to 1.49 seconds occurred on September 6, but it did not disrupt consensus. Connection drops averaged 84.6 incidents per five-minute period, which was characterized as normal background activity.

Most notably, the hub’s “Abuse” metric dropped to nearly zero, indicating that the updated protections are successfully filtering most malicious or unwanted traffic.

The results provide an early real-world test of xrpld 3.2.1 following the July attack. While the metrics cover Schwartz’s private hub rather than every XRPL node, they suggest the software changes have significantly strengthened the infrastructure against similar manifest-flooding attempts.

<Copyright ⓒ TokenPost, unauthorized reproduction and redistribution prohibited>

Most Popular

Comment 0

Comment tips

Great article. Requesting a follow-up. Excellent analysis.

0/1000

Comment tips

Great article. Requesting a follow-up. Excellent analysis.
1