XRP Ledger Foundation confirms SDK breach and issues urgent fix

Source Cryptopolitan

Software security firm Aikodo has alerted XRP Ledger developers to a vulnerability in the XRPL software development kit (SDK) that allows hackers to steal private keys. The developer-focused firm said the vulnerability was in XRPL versions 4.2.1 – 4.2.4.

According to the firm, it first identified the vulnerability on April 21, 20:53 GMT+0, after it got an alert of five new packages added to the XRPL package. A closer examination showed that bad actors had compromised the package by adding a backdoor to steal private keys.

It said:

“We quickly confirmed the official XPRL (Ripple) NPM package was compromised by sophisticated attackers who put in a backdoor to steal cryptocurrency private keys and gain access to cryptocurrency wallets.”

Given that the package has an average of 140,000 weekly downloads and thousands of websites and applications use it, the incident could have been a disastrous supply chain attack for the crypto industry.

Per the report, the hacker used several versions of the package in an attempt to hide their trail and make sure the vulnerability was not visible. However, Aikido was able to identify it due to its Aikido Intel tool that monitors public package managers such as NPM and identifies any malicious code changes.

XRPL Foundation acknowledges compromise

Meanwhile, the XRPL Foundation, the non-profit behind the XRPL network, has acknowledged the incident and deployed a fix to the vulnerability. The foundation said on X that it has now published a version 4.2.5 of the XRPL package as a replacement for the compromised versions.

Developers who have the compromised versions have been advised to replace them immediately. The foundation also deprecated all the compromised versions on NPM so that no one can download them.

It also advised that developers should be using the latest v4.2.5 or the much older v2.14.3, which was not compromised and added that that the issue does not affect the XRPL codebase or its GitHub repository.

The foundation said:

“This vulnerability is in xrpl.js, a JavaScript library for interacting with the XRP Ledger. It does NOT affect the XRP Ledger codebase or Github repository itself. Projects using xrpl.js should upgrade to v4.2.5 immediately.”

So far, several protocols on the network have confirmed that the vulnerability did affect them. Xaman Wallet noted that it uses in-house infrastructure and libraries to handle transactions and private keys, while XRPScan said it uses an older version of the xrpl.js and does not process private keys.

Others, such as Bitfrost wallet, DeFi protocol OpulenceX, memecoin RibbleXRP, and Web3 gaming platform Gen3 Games have also confirmed they are unaffected.

Crypto-related supply chain attacks becoming prevalent

The XRPL supply chain attack is the latest incident of bad actors targeting software packages to exploit crypto-related projects.

Back in March, hackers targeted Coinbase in a GitHub Actions supply chain attack by trying to break the exchange’s open-source AgentKit. However, they failed at it, and Coinbase foiled the attempt, deciding to attack several repositories instead.

Before that, cybersecurity experts have discovered that the notorious North Korean hacker group, Lazarus, is targeting crypto developers using NPM repositories and creating backdoors in projects. It is unclear whether they are involved in the

Cryptopolitan Academy: Tired of market swings? Learn how DeFi can help you build steady passive income. Register Now

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Australian Dollar appreciates amid rising concerns about Fed’s independenceThe Australian Dollar (AUD) extends its gains against the US Dollar (USD) on Tuesday.
Author  FXStreet
4 Month 22 Day Tue
The Australian Dollar (AUD) extends its gains against the US Dollar (USD) on Tuesday.
placeholder
Dogecoin lead double-digit gains across meme coins, with Shiba Inu, PEPE and BONK skyrocketing to new monthly highsTop meme coins Dogecoin (DOGE), Shiba Inu (SHIB), PEPE and BONK lead the meme coin sector with double-digit gains on Wednesday following the crypto market recovery.
Author  FXStreet
21 hours ago
Top meme coins Dogecoin (DOGE), Shiba Inu (SHIB), PEPE and BONK lead the meme coin sector with double-digit gains on Wednesday following the crypto market recovery.
placeholder
EUR/USD Price Forecast: Bounces off 1.1300 neighborhood; shows resilience below 23.6% Fibo.The EUR/USD pair attracts some follow-through selling for the second straight day on Wednesday and drops to a one-week low during the Asian session. Spot prices, however, rebound a few pips from the 1.1300 neighborhood and currently trade around the 1.1380 region, still down over 0.35% for the day.
Author  FXStreet
21 hours ago
The EUR/USD pair attracts some follow-through selling for the second straight day on Wednesday and drops to a one-week low during the Asian session. Spot prices, however, rebound a few pips from the 1.1300 neighborhood and currently trade around the 1.1380 region, still down over 0.35% for the day.
placeholder
Top 3 gainers Fartcoin, Zerebro, DeepBook: Solana and Sui meme coins soar on bold risk-on waveMeme coins led by Fartcoin, Zerebro and DeepBook (DEEP) are extending gains during the Asian session on Wednesday amid soaring investor risk appetite. Bitcoin (BTC) briefly crossed $93,000 the previous day alongside widespread rallies among altcoins.
Author  FXStreet
21 hours ago
Meme coins led by Fartcoin, Zerebro and DeepBook (DEEP) are extending gains during the Asian session on Wednesday amid soaring investor risk appetite. Bitcoin (BTC) briefly crossed $93,000 the previous day alongside widespread rallies among altcoins.
placeholder
Top 3 Price Prediction Bitcoin, Ethereum, Ripple: Bulls target $95,000 BTC, $1,900 ETH, and $3 XRPBitcoin (BTC) price hovers around $92,800 on Wednesday after rallying 9.75% over the past two days. Ethereum (ETH) and Ripple (XRP) followed BTC’s footsteps and continued their recovery rally. The technical outlook suggests an upward trend, targeting $95,000 BTC, $1,900 ETH, and $3 XRP.
Author  FXStreet
21 hours ago
Bitcoin (BTC) price hovers around $92,800 on Wednesday after rallying 9.75% over the past two days. Ethereum (ETH) and Ripple (XRP) followed BTC’s footsteps and continued their recovery rally. The technical outlook suggests an upward trend, targeting $95,000 BTC, $1,900 ETH, and $3 XRP.
goTop
quote