Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025
    Facebook X (Twitter) Instagram
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    Ai Crypto TimesAi Crypto Times
    Home » XRP Ledger Foundation issues urgent patch for compromised XRPL SDK

    XRP Ledger Foundation issues urgent patch for compromised XRPL SDK

    Isabella TaylorBy Isabella TaylorApril 23, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    The XRP Ledger Foundation has patched a critical vulnerability within its official JavaScript SDK that could have allowed attackers to steal private keys and drain cryptocurrency wallets.

    On April 22, the XRP Ledger Foundation released an updated version of the XRP Ledger npm package, removing the compromised code and restoring safe functionality for developers building on the network.

    The xrpl npm package is the official JavaScript/TypeScript library for interacting with the XRP Ledger. Developers use it to connect to the network, manage wallets, send transactions, and build decentralized applications using XRPL functionalities.

    The update came just hours after blockchain security firm Aikido flagged suspicious activity in five newly published versions of the library. 

    According to Aikido’s report, bad actors had published fake versions of the package to npm, starting with 4.2.1. These versions did not match any official releases on GitHub, an early red flag that helped Aikido’s automated systems detect the anomaly.

    Notably, bad actors had “put in a backdoor to steal cryptocurrency private keys and gain access to cryptocurrency wallets.”

    These rogue packages included hidden code that quietly siphoned private keys by pinging a malicious domain 0x9c.xyz controlled by them. The malicious function was triggered whenever a new wallet was created, effectively handing over control of funds to the attacker.

    Aikido labelled the vulnerability as “potentially catastrophic,” calling it one of the worst kinds of supply chain attacks in crypto.

    Since the xrpl package sees over 140,000 weekly downloads and is embedded in hundreds of thousands of websites and apps, the backdoor had the potential to compromise a massive swath of the XRP ecosystem almost silently.

    The attacker was also seen refining the malicious packages with each release. Early versions (4.2.1 and 4.2.2) included changes only in built JavaScript files, likely to avoid triggering suspicion during typical code reviews. Later versions, like 4.2.3 and 4.2.4, injected the malicious code directly into the TypeScript source files, allowing the payload to persist across builds.

    Aikido researchers urged users to immediately stop using the affected versions and rotate any private keys or seed phrases that may have been exposed. They also recommended scanning network logs for connections to the domain 0x9c.xyz and upgrading to the patched versions, 4.2.5 or 2.14.3, to ensure continued security.

    In follow-up updates, the foundation confirmed that the compromised packages had been removed and that key projects, such as XRPScan, First Ledger, and Gen3 Games, were not affected.

    The incident didn’t rattle traders; XRP was up 7.4% over the past 24 hours, trading at $2.24 at the time of writing.

    As previously reported by crypto.news, the XRP Ledger faced another major incident earlier this year when a disruption in transaction validation halted the network for nearly an hour on Feb. 5. However, no data loss was reported during the incident.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Isabella Taylor

    Related Posts

    S&P 500 ends higher while Dow slips, tariff relief boosts tech stocks

    May 14, 2025

    5 Best API Documentation Tools EVER! 2025

    May 14, 2025

    Best 7 KYC API to look out for | Check NOW! 2025

    May 14, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    Lithosphere News Releases May 15, 2025

    … growing infrastructure vulnerabilities. AGII’s AI-powered detection … Unlike static security frameworks, AGII’s approach leverages…

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    • Popular
    • Recent
    • Top Reviews

    30 Minutes of Exercise vs 100 Steps a Day: Which One is Better?

    May 16, 2021

    Quisque consectetur libero elit

    September 1, 2020

    Winter Fitness: These Poses Can Keep You Warm

    January 14, 2021

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025
    9.3

    Facilisis tincidunt justo eget urna leo dapibus at

    December 19, 2020
    8.9

    Review: Denmark Proposes Corona Pass Mandate for Workers

    January 9, 2020
    8.9

    Laoreet Sed: Suscipit nec dapibus at elit

    December 19, 2020
    Latest Galleries
    [latest_gallery cat="all" number="5" type="slider"]
    Latest Reviews
    8.5

    Review: How Research Could Help with Spinal Cord Injuries

    March 14, 2021
    8.9

    Review: How AI in Soccer could Predict Injuries?

    January 15, 2021
    8.9

    Review: Can Wisconsin Clinch the Big Ten West this Weekend

    January 15, 2021
    Demo
    Top Posts

    Atua AI Extends Bitcoin-Backed Infrastructure for Intelligent Enterprise Operations

    April 23, 202513 Views

    AGII Launches AI-Powered Web3 App To Advance Real-Time Decentralized Infrastructure

    April 26, 20251 Views

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 20250 Views

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 20250 Views
    Don't Miss

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    Lithosphere News Releases May 15, 2025

    … growing infrastructure vulnerabilities. AGII’s AI-powered detection … Unlike static security frameworks, AGII’s approach leverages…

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    Top Posts

    Atua AI Extends Bitcoin-Backed Infrastructure for Intelligent Enterprise Operations

    April 23, 202513 Views

    AGII Launches AI-Powered Web3 App To Advance Real-Time Decentralized Infrastructure

    April 26, 20251 Views

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 20250 Views

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 20250 Views
    Don't Miss

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    Lithosphere News Releases May 15, 2025

    … growing infrastructure vulnerabilities. AGII’s AI-powered detection … Unlike static security frameworks, AGII’s approach leverages…

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025

    AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience

    May 15, 2025
    Recent Posts
    • AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience
    • AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience
    • AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience
    • AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience
    • AGII Deploys Smart Detection Models for On-Chain Infrastructure Resilience
    © 2025 - 2026

    Type above and press Enter to search. Press Esc to cancel.