XRP Ledger Compromised? Validator Warns Projects And Developers Of Critical Issues

Source Bitcoinist

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues on the network, which put users and their funds at risk of an exploit. 

Validator Warns That XRP Ledger is Compromised

In an X post, XRP Ledger validator Vet told the network’s developers and projects that use the XRPL js library not to update or use any version 4.2.1 or higher, as it has been compromised. He remarked that any project utilizing the newest version of XRPL is putting users and funds at risk of an attack from hackers. 

Vet’s warning was in response to a post by Aikido Security, in which they stated that they had discovered a backdoor in the official XRP Ledger NPM package. The blockchain security firm added that this back door steals private keys and sends them to attackers. The affected versions are 4.2.1 and 4.2.4, so developers and projects should not upgrade to these versions. 

Ripple Chief Technology Officer (CTO) David Schwartz also commented on the Ledger situation, noting that it was just the XRPL.js from NPM that was compromised. He also alluded to a post by Ripple senior software engineer Mayukha Vadari. Vadari mentioned that the Ledger itself is unaffected by the malware. 

The engineer confirmed that the malware packages only affected services that use xrpl.js and were upgraded to the malicious versions that were published about a day ago. He added that GitHub remains safe, as only npm has been compromised. Vadari urged users to avoid services that have access to their private keys and seed phrases until they have confirmed that these services are unaffected by this malware. 

XRPL Foundation Provides Update 

The XRP Ledger Foundation also provided an update on the malware situation. In an X post, the Foundation clarified that the vulnerability is in xrpl.js, a JavaScript library for interacting with the XRPL. They further stated that the vulnerability does not affect the network’s codebase or the GitHub repository itself. Meanwhile, the Foundation urged projects using xrpl.js to upgrade to v4.2.5 immediately. 

The XRP Ledger Foundation also confirmed in the thread that it had deprecated the compromised xrpl.js versions on npm. They mentioned that they will share a detailed post-mortem soon and again urged projects and developers to ensure that they are using versions 4.2.5 or 2.14.3. 

In another X post, the Foundation announced that it has published an updated npm package for users of the 2.14.x branch to remove the previously compromised version. They asked these XRP Ledger users to update immediately to version 2.14.3 to prevent an attack. 

XRP
Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
XRP Price Prediction: Fibonacci And Elliott Wave Analysis Suggests $15 By May 2025Egrag Crypto, a well-known crypto analyst on the social media platform X, recently shared an optimistic price prediction for XRP. According to the analyst, technical analysis of the XRP price on the
Author  NewsBTC
Dec 30, 2024
Egrag Crypto, a well-known crypto analyst on the social media platform X, recently shared an optimistic price prediction for XRP. According to the analyst, technical analysis of the XRP price on the
placeholder
Ripple (XRP) Price Sees a Surge, Solana Targets $600 in 2025 as Investors Increase Focus on New AltcoinThe cryptocurrency market is showing renewed momentum as Ripple (XRP) experiences a significant price surge, and Solana (SOL) sets its sights on a bold $600 target by 2025. Meanwhile, a rising altcoin, Lightchain AI, is capturing investor attention with its innovative ecosystem and strong presale performance, making it a compelling choice for forward-looking investors. Ripple […]
Author  Cryptopolitan
Jan 15, Wed
The cryptocurrency market is showing renewed momentum as Ripple (XRP) experiences a significant price surge, and Solana (SOL) sets its sights on a bold $600 target by 2025. Meanwhile, a rising altcoin, Lightchain AI, is capturing investor attention with its innovative ecosystem and strong presale performance, making it a compelling choice for forward-looking investors. Ripple […]
placeholder
What Crypto Whales are Buying For May 2025Crypto whales are making bold moves heading into May 2025, and three tokens are standing out: Ethereum (ETH), Artificial Superintelligence Alliance (FET), and Onyxcoin (XCN).
Author  Beincrypto
Apr 21, Mon
Crypto whales are making bold moves heading into May 2025, and three tokens are standing out: Ethereum (ETH), Artificial Superintelligence Alliance (FET), and Onyxcoin (XCN).
placeholder
Gold Price Forecast: XAU/USD attracts some sellers below $3,250 on firmer US DollarThe Gold price (XAU/USD) extends the decline to around $3,245 during the early Asian session on Thursday. The precious metal edges lower to near a two-week low amid easing US-China trade tensions and stronger US Dollar (USD) demand. 
Author  FXStreet
May 01, Thu
The Gold price (XAU/USD) extends the decline to around $3,245 during the early Asian session on Thursday. The precious metal edges lower to near a two-week low amid easing US-China trade tensions and stronger US Dollar (USD) demand. 
placeholder
Gold Price Forecast: XAU/USD edges higher to near $3,250 as trade questions lingerThe Gold price (XAU/USD) trades in positive territory near $3,245 during the early Asian session on Monday. The renewed concerns over the US recession and US-China trade relations provide some support to safe-haven assets like Gold.
Author  FXStreet
Yesterday 01: 29
The Gold price (XAU/USD) trades in positive territory near $3,245 during the early Asian session on Monday. The renewed concerns over the US recession and US-China trade relations provide some support to safe-haven assets like Gold.
goTop
quote