The XRP Ledger (XRPL) infrastructure has returned to normal operation following the widespread network disruption caused by a manifest flood attack in July. Telemetry data provided by XRPL engineer and Ripple CTO Emeritus David Schwartz indicate that the network’s stability has been restored, with private nodes operating reliably through early September.
XRPL recovers after manifest flood attack
David Schwartz released performance statistics from his personal XRPL node, spanning August 25 to September 8. He described his node’s performance as “rock solid,” suggesting that recent updates have helped the XRPL network bounce back from the July attack.
On July 31, attackers targeted XRPL nodes with a “manifest storm,” overwhelming the network’s infrastructure by transmitting thousands of counterfeit manifest certificates. Validator nodes, responsible for processing these certificates, experienced significant connection issues during the incident.
Connection problems reported by Schwartz’s hub at the time included “onReadMessage” errors, primarily observed when nodes checked their ledger states. Despite these disruptions, XRPL’s consensus mechanism remained unaffected, and new ledger creation was not interrupted.
In response, XRPL developers released the xrpld 3.2.1 hotfix, introducing multiple safeguards. Limits were imposed on manifest file sizes, and data caching protocols for unknown network participants were adjusted to block potentially suspicious connections and minimize their impact on system resources.
More than a month after the attack, Schwartz’s telemetry data offers insights into the durability of these countermeasures under day-to-day network conditions.
Recent telemetry shows that the XRP Ledger’s new security measures are effectively filtering out most undesirable traffic, resulting in stable network performance and minimal disruptions since the July incident.
In rapidly moving crypto markets, where a single Fed decision or sudden altcoin listing can swing prices in seconds, traders now prefer keeping real-time charts, macro data, and portfolio updates all in one place. Instead of toggling between multiple applications and losing valuable reaction time, many are opting for privacy-first tools like CryptoAppsy, which deliver live charts, custom alerts, coin news, and market data on a single screen without requiring account creation.
Network metrics indicate stabilization
According to Schwartz, his private XRPL node managed around 400 concurrent connections between August 25 and September 8. Out of 423 connections, 135 were inbound while 271 were outbound. Peer latency averaged 165 milliseconds, with only a brief spike—reaching 1.49 seconds on September 6—that did not disturb overall network consensus.
Schwartz observed an average of 84.6 connection losses every five minutes, which he categorized as routine background activity for the node hub. The most significant change was found in the “Abuse” metric, which dropped to nearly zero levels. This suggests that the new software update has succeeded in blocking most unwanted or potentially malicious traffic, thereby preventing excess strain on the network’s nodes.
Software improvements strengthen security outlook
The latest telemetry provides early evidence that the security enhancements introduced in xrpld 3.2.1 have improved XRPL’s defenses against manifest-style attacks. While Schwartz’s node data may not represent every node across the entire XRPL network, the sustained stability, low latency, and reduced abuse figures point to an overall increase in resilience.
The July disruption left ledger finality intact, and the implemented software changes now appear to be ensuring that XRPL nodes are better equipped to withstand similar threats in the future.
Although these findings draw from a private node setup, they offer a clear indication that XRPL’s network infrastructure has responded well to the most recent round of developer-implemented security upgrades.




