XRP Ledger Compromised? Validator Warns Projects And Developers Of Critical Issues

bitcoinistPublished on 2025-04-23Last updated on 2025-04-23

Abstract

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues on the network, which put users and their funds at risk of an exploit. 

Validator Warns That XRP Ledger is Compromised

In an X post, XRP Ledger validator Vet told the network’s developers and projects that use the XRPL js library not to update or use any version 4.2.1 or higher, as it has been compromised. He remarked that any project utilizing the newest version of XRPL is putting users and funds at risk of an attack from hackers. 

Vet’s warning was in response to a post by Aikido Security, in which they stated that they had discovered a backdoor in the official XRP Ledger NPM package. The blockchain security firm added that this back door steals private keys and sends them to attackers. The affected versions are 4.2.1 and 4.2.4, so developers and projects should not upgrade to these versions. 

Ripple Chief Technology Officer (CTO) David Schwartz also commented on the Ledger situation, noting that it was just the XRPL.js from NPM that was compromised. He also alluded to a post by Ripple senior software engineer Mayukha Vadari. Vadari mentioned that the Ledger itself is unaffected by the malware. 

The engineer confirmed that the malware packages only affected services that use xrpl.js and were upgraded to the malicious versions that were published about a day ago. He added that GitHub remains safe, as only npm has been compromised. Vadari urged users to avoid services that have access to their private keys and seed phrases until they have confirmed that these services are unaffected by this malware. 

XRPL Foundation Provides Update 

The XRP Ledger Foundation also provided an update on the malware situation. In an X post, the Foundation clarified that the vulnerability is in xrpl.js, a JavaScript library for interacting with the XRPL. They further stated that the vulnerability does not affect the network’s codebase or the GitHub repository itself. Meanwhile, the Foundation urged projects using xrpl.js to upgrade to v4.2.5 immediately. 

The XRP Ledger Foundation also confirmed in the thread that it had deprecated the compromised xrpl.js versions on npm. They mentioned that they will share a detailed post-mortem soon and again urged projects and developers to ensure that they are using versions 4.2.5 or 2.14.3. 

In another X post, the Foundation announced that it has published an updated npm package for users of the 2.14.x branch to remove the previously compromised version. They asked these XRP Ledger users to update immediately to version 2.14.3 to prevent an attack. 

XRP
XRP trading at $2.2 on the 1D chart | Source: XRPUSDT on Tradingview.com
Featured image from YouTube, chart from Tradingview.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Scott Matherson is a leading crypto writer at Bitcoinist, who possesses a sharp analytical mind and a deep understanding of the digital currency landscape. Scott has earned a reputation for delivering thought-provoking and well-researched articles that resonate with both newcomers and seasoned crypto enthusiasts. Outside of his writing, Scott is passionate about promoting crypto literacy and often works to educate the public on the potential of blockchain.

Related Reads

Chen Maobo and Others Revealed as First Batch of Guests for the 2026 Hong Kong Web3 Carnival!

The 2026 Hong Kong Web3 Carnival, co-organized by Wanxiang Blockchain Lab and HashKey Group, will take place from April 20 to 23, 2026, at the Hong Kong Convention and Exhibition Centre. This annual event aims to bridge traditional and innovative sectors while connecting Eastern and Western global perspectives. Confirmed speakers include prominent figures such as Paul Chan Mo-po, Financial Secretary of the Hong Kong SAR; Xiao Feng, Chairman of Wanxiang Blockchain and HashKey Group; and other industry leaders from Solana Foundation, MatrixPort, and Animoca Brands, among others. The event is supported by strategic partners like the Hong Kong Trade Development Council and sponsors including OKX Web3 and Qtum. The carnival has attracted significant cross-industry interest, with over 500 executives from traditional finance and实体 industries registered by December 2025, highlighting its role in fostering dialogue between Web3 innovation and established sectors. Since its inception in 2023, the Hong Kong Web3 Carnival has grown into one of the world's most influential crypto summits, with past editions drawing over 100,000 attendees, 350 projects, and 1,200 speakers. The 2026 edition will continue to leverage Hong Kong’s unique position to deepen global integration of technology, business models, and regulatory practices, while providing a platform for local developers and projects to gain international exposure.

比推7m ago

Chen Maobo and Others Revealed as First Batch of Guests for the 2026 Hong Kong Web3 Carnival!

比推7m ago

From Doubao Dispute to Big Tech Game: Decoding the Legal Compliance Dilemma of AI Phones

"From Doubao Controversy to Tech Giant Standoff: Decoding the Legal Compliance Dilemma of AI Phones" A recent user experience with AI-powered smartphones has triggered significant tension between AI developers and major internet platforms. Certain phones equipped with AI assistants, when attempting to perform automated actions like sending WeChat red packets or placing e-commerce orders via voice commands, were flagged by platforms for "suspected use of third-party plugins," leading to risk warnings and even account restrictions. This incident, while appearing to be a technical compatibility issue, reveals a deeper structural conflict over "who has the right to operate the phone and control user access." On one side are smartphone manufacturers and AI teams aiming to deeply integrate AI into operating systems for "seamless interaction." On the other are internet platforms whose business models rely on controlling app entry points, user pathways, and data ecosystems. This clash represents a fundamental challenge to the "walled garden" business model central to platforms like Tencent and Alibaba. The system-level AI assistant threatens this model in three key ways: it bypasses the need to click app icons (undermining ad revenue and user attention economies), potentially accesses platform data and content without formal interfaces (a "free-riding" concern), and shifts the role of "gatekeeper" for traffic distribution away from the super apps themselves. From a legal perspective, this conflict highlights four major risk areas: 1. **Competition Law:** AI's "simulated clicks" could be deemed unauthorized interference with software operation, potentially constituting unfair competition if they skip ads or bypass verification steps. 2. **Data Security:** For the AI to "see" screen content and execute commands, it processes sensitive personal data (chats, account info), raising significant questions under China's Personal Information Protection Law regarding valid user consent and the "minimum necessity" principle. 3. **Antitrust Issues:** Future disputes may center on whether dominant platforms, arguably essential facilities, can justifiably refuse AI access, or if such refusal constitutes an abuse of market power that stifles innovation. 4. **User Liability:** Questions arise regarding who is responsible if the AI makes an error (e.g., buys the wrong product) or if a user's account is suspended due to AI activity, potentially leading to consumer claims against phone manufacturers. This friction underscores a transition from an app-centric internet to an AI-agent-driven experience. The current legal framework struggles to address the integration of general AI. The sustainable solution likely lies not in technical workarounds like "simulated clicks," but in developing standardized protocols for AI interaction, balancing innovation with clear legal and compliance boundaries.

深潮21m ago

From Doubao Dispute to Big Tech Game: Decoding the Legal Compliance Dilemma of AI Phones

深潮21m ago

Trading

Spot
Futures
活动图片