The route hijack RPKI called valid: the ROA allowed all the way down to /24
Between 28 and 30 August 2026, a BGP hijack diverted traffic for 162.55.80.0/24 across some 22 active hours and served a malicious update from behind a valid TLS certificate. We went and checked the ROA on RIPEstat: until 1 September it carried maxLength 24, so while the hijack lasted the route was RPKI valid. What origin validation checks and what it does not, why that same maxLength was also the cure, and the six verifications you can run today.