XRP Ledger Compromised? Validator Warns Projects And Developers Of Critical Issues

Source Bitcoinist

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues on the network, which put users and their funds at risk of an exploit. 

Validator Warns That XRP Ledger is Compromised

In an X post, XRP Ledger validator Vet told the network’s developers and projects that use the XRPL js library not to update or use any version 4.2.1 or higher, as it has been compromised. He remarked that any project utilizing the newest version of XRPL is putting users and funds at risk of an attack from hackers. 

Vet’s warning was in response to a post by Aikido Security, in which they stated that they had discovered a backdoor in the official XRP Ledger NPM package. The blockchain security firm added that this back door steals private keys and sends them to attackers. The affected versions are 4.2.1 and 4.2.4, so developers and projects should not upgrade to these versions. 

Ripple Chief Technology Officer (CTO) David Schwartz also commented on the Ledger situation, noting that it was just the XRPL.js from NPM that was compromised. He also alluded to a post by Ripple senior software engineer Mayukha Vadari. Vadari mentioned that the Ledger itself is unaffected by the malware. 

The engineer confirmed that the malware packages only affected services that use xrpl.js and were upgraded to the malicious versions that were published about a day ago. He added that GitHub remains safe, as only npm has been compromised. Vadari urged users to avoid services that have access to their private keys and seed phrases until they have confirmed that these services are unaffected by this malware. 

XRPL Foundation Provides Update 

The XRP Ledger Foundation also provided an update on the malware situation. In an X post, the Foundation clarified that the vulnerability is in xrpl.js, a JavaScript library for interacting with the XRPL. They further stated that the vulnerability does not affect the network’s codebase or the GitHub repository itself. Meanwhile, the Foundation urged projects using xrpl.js to upgrade to v4.2.5 immediately. 

The XRP Ledger Foundation also confirmed in the thread that it had deprecated the compromised xrpl.js versions on npm. They mentioned that they will share a detailed post-mortem soon and again urged projects and developers to ensure that they are using versions 4.2.5 or 2.14.3. 

In another X post, the Foundation announced that it has published an updated npm package for users of the 2.14.x branch to remove the previously compromised version. They asked these XRP Ledger users to update immediately to version 2.14.3 to prevent an attack. 

XRP
Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Top 3 Price Prediction Bitcoin, Ethereum, Ripple: Bulls target $95,000 BTC, $1,900 ETH, and $3 XRPBitcoin (BTC) price hovers around $92,800 on Wednesday after rallying 9.75% over the past two days. Ethereum (ETH) and Ripple (XRP) followed BTC’s footsteps and continued their recovery rally. The technical outlook suggests an upward trend, targeting $95,000 BTC, $1,900 ETH, and $3 XRP.
Author  FXStreet
12 hours ago
Bitcoin (BTC) price hovers around $92,800 on Wednesday after rallying 9.75% over the past two days. Ethereum (ETH) and Ripple (XRP) followed BTC’s footsteps and continued their recovery rally. The technical outlook suggests an upward trend, targeting $95,000 BTC, $1,900 ETH, and $3 XRP.
placeholder
Bitcoin Must Clear This Critical Cost Basis Level For Continued Upside, Analyst SaysIn a recent CryptoQuant Quicktake post, contributor Crazzyblockk highlighted key Bitcoin (BTC) cost basis zones that the leading cryptocurrency must clear – or avoid breaking below – to
Author  NewsBTC
12 hours ago
In a recent CryptoQuant Quicktake post, contributor Crazzyblockk highlighted key Bitcoin (BTC) cost basis zones that the leading cryptocurrency must clear – or avoid breaking below – to
placeholder
Top 3 gainers Fartcoin, Zerebro, DeepBook: Solana and Sui meme coins soar on bold risk-on waveMeme coins led by Fartcoin, Zerebro and DeepBook (DEEP) are extending gains during the Asian session on Wednesday amid soaring investor risk appetite. Bitcoin (BTC) briefly crossed $93,000 the previous day alongside widespread rallies among altcoins.
Author  FXStreet
12 hours ago
Meme coins led by Fartcoin, Zerebro and DeepBook (DEEP) are extending gains during the Asian session on Wednesday amid soaring investor risk appetite. Bitcoin (BTC) briefly crossed $93,000 the previous day alongside widespread rallies among altcoins.
placeholder
EUR/USD Price Forecast: Bounces off 1.1300 neighborhood; shows resilience below 23.6% Fibo.The EUR/USD pair attracts some follow-through selling for the second straight day on Wednesday and drops to a one-week low during the Asian session. Spot prices, however, rebound a few pips from the 1.1300 neighborhood and currently trade around the 1.1380 region, still down over 0.35% for the day.
Author  FXStreet
12 hours ago
The EUR/USD pair attracts some follow-through selling for the second straight day on Wednesday and drops to a one-week low during the Asian session. Spot prices, however, rebound a few pips from the 1.1300 neighborhood and currently trade around the 1.1380 region, still down over 0.35% for the day.
placeholder
BNB Price Reclaims $600 — Is This the Start of a Major Upside Move?BNB price is rising from the $580 support zone. The price is now consolidating gains above $600 and might aim for more gains in the near term. BNB price is attempting to recover above the $615
Author  FXStreet
12 hours ago
BNB price is rising from the $580 support zone. The price is now consolidating gains above $600 and might aim for more gains in the near term. BNB price is attempting to recover above the $615
goTop
quote