started · updated
XRP Ledger stabilizes after manifest storm attack and usage scrutiny
The XRP Ledger (XRPL) infrastructure has stabilized following a “manifest storm” attack in July. During the incident, hackers sent thousands of counterfeit manifest certificates to the network, causing connection issues for validator nodes. However, the attack did not impact the network's ability to reach consensus on new ledgers. David Schwartz, Ripple CTO Emeritus, reported that recent telemetry data shows the network infrastructure has bounced back and is performing reliably.
Separately, the network is facing scrutiny regarding its transaction composition. Data from Bitquery indicated that in August 2026, a small group of 793 accounts accounted for 93.2% of XRPL transactions. Critics used this data to label the network a “ghost chain,” suggesting that most activity is machine-generated or spam.
Schwartz and other supporters defended the network, arguing that low transaction costs naturally facilitate a high volume of both high-value and low-value activities. Meanwhile, technical development continues with the xrpld 3.3.0 Permission Delegation amendment moving toward the validator voting process, which aims to allow institutions to assign specific operational functions through role-based permissions.