XRP Ledger Compromised? Validator Warns Projects And Developers Of Critical Issues

bitcoinistPubblicato 2025-04-23Pubblicato ultima volta 2025-04-23

Introduzione

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues on the network, which put users and their funds at risk of an exploit. 

Validator Warns That XRP Ledger is Compromised

In an X post, XRP Ledger validator Vet told the network’s developers and projects that use the XRPL js library not to update or use any version 4.2.1 or higher, as it has been compromised. He remarked that any project utilizing the newest version of XRPL is putting users and funds at risk of an attack from hackers. 

Vet’s warning was in response to a post by Aikido Security, in which they stated that they had discovered a backdoor in the official XRP Ledger NPM package. The blockchain security firm added that this back door steals private keys and sends them to attackers. The affected versions are 4.2.1 and 4.2.4, so developers and projects should not upgrade to these versions. 

Ripple Chief Technology Officer (CTO) David Schwartz also commented on the Ledger situation, noting that it was just the XRPL.js from NPM that was compromised. He also alluded to a post by Ripple senior software engineer Mayukha Vadari. Vadari mentioned that the Ledger itself is unaffected by the malware. 

The engineer confirmed that the malware packages only affected services that use xrpl.js and were upgraded to the malicious versions that were published about a day ago. He added that GitHub remains safe, as only npm has been compromised. Vadari urged users to avoid services that have access to their private keys and seed phrases until they have confirmed that these services are unaffected by this malware. 

XRPL Foundation Provides Update 

The XRP Ledger Foundation also provided an update on the malware situation. In an X post, the Foundation clarified that the vulnerability is in xrpl.js, a JavaScript library for interacting with the XRPL. They further stated that the vulnerability does not affect the network’s codebase or the GitHub repository itself. Meanwhile, the Foundation urged projects using xrpl.js to upgrade to v4.2.5 immediately. 

The XRP Ledger Foundation also confirmed in the thread that it had deprecated the compromised xrpl.js versions on npm. They mentioned that they will share a detailed post-mortem soon and again urged projects and developers to ensure that they are using versions 4.2.5 or 2.14.3. 

In another X post, the Foundation announced that it has published an updated npm package for users of the 2.14.x branch to remove the previously compromised version. They asked these XRP Ledger users to update immediately to version 2.14.3 to prevent an attack. 

XRP
XRP trading at $2.2 on the 1D chart | Source: XRPUSDT on Tradingview.com
Featured image from YouTube, chart from Tradingview.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Scott Matherson is a leading crypto writer at Bitcoinist, who possesses a sharp analytical mind and a deep understanding of the digital currency landscape. Scott has earned a reputation for delivering thought-provoking and well-researched articles that resonate with both newcomers and seasoned crypto enthusiasts. Outside of his writing, Scott is passionate about promoting crypto literacy and often works to educate the public on the potential of blockchain.

Letture associate

Musk Posted a Recruitment Ad for SpaceX, and After Reading the Comments Section, I Understood

On May 20th, SpaceX filed for a landmark IPO with a $1.75 trillion valuation. Shortly after, Elon Musk posted a recruitment call on X, seeking "world-class engineers and physicists" for SpaceX. The application process was starkly simple: email with three bullet points proving "exceptional ability," with real, complex projects as a plus. Musk promised to review qualifying emails himself. The post garnered millions of views and thousands of replies, revealing a spectrum of responses. Most comments, including a highly-upvoted humorous one listing absurd "skills," merely listed credentials or experiences in a conventional, non-differentiating way. This highlighted a key insight: a traditional resume listing degrees and skills often fails to demonstrate true exceptionalism. Effective self-presentation requires "performance efficiency." A standout reply came from an OpenAI engineering lead, who simply stated "codex." This demonstrated that for those who have built significant, recognized products, the product itself becomes the ultimate resume. The article argues that in the AI era, any tangible, shareable output—a tool, research, or online project—serves as a living, self-evident credential more powerful than a list of attributes. However, a twist emerged when applicants found the provided email address non-functional, leading to speculation that the post might also serve as an IPO publicity stunt, projecting an image of aggressive talent acquisition to investors. Ultimately, the episode served as a microcosm: some participate through performance, others through proof of work, while some question the reality of the stage itself. It underscores the enduring challenge of defining and demonstrating value in an age of abundant, yet often superficial, content.

marsbit39 min fa

Musk Posted a Recruitment Ad for SpaceX, and After Reading the Comments Section, I Understood

marsbit39 min fa

Cutting Off OpenAI, Anthropic Acquires the Tool Provider Used by a Quarter of Global Developers

Anthropic has acquired Stainless, a developer tool company that automatically generated official SDKs (Software Development Kits) for AI giants including OpenAI, Anthropic, Meta, and Cloudflare. The deal, reportedly valued at around $300 million, marks a strategic shift for Anthropic as it builds its "AI agent" infrastructure. Stainless acted as a "translator," converting complex API specifications into ready-to-use code libraries for developers. Its tools indirectly reached about a quarter of professional software developers globally. Following the acquisition, Stainless will shut down its public products and its team will join Anthropic to focus on internal platform development, notably for the Claude Platform. Existing SDKs remain with their respective client companies but will no longer receive updates from Stainless. This move is part of Anthropic's broader 18-month strategy to assemble a complete "agent stack." The stack consists of the Claude model at its core, the newly acquired Stainless for standardized API interfaces, and the Model Context Protocol (MCP), an open standard for connecting agents to external tools and data. This contrasts with OpenAI's focus on model generations and consumer-scale compute. Anthropic believes an agent's ultimate utility depends on its ability to connect to external systems. By internalizing the SDK layer and promoting MCP as a connection standard, Anthropic aims to lock in long-term ecosystem advantages and create path dependency, moving beyond the transient lead provided by any single model generation.

marsbit40 min fa

Cutting Off OpenAI, Anthropic Acquires the Tool Provider Used by a Quarter of Global Developers

marsbit40 min fa

Bankless Founder Sells Off ETH, Collective Collapse of Ethereum Faith

Ethereum faces a "crisis of faith" as David Hoffman, co-founder of the prominent pro-Ethereum media outlet Bankless, announces he has sold all his ETH. This move, coupled with reports of major layoffs at Bankless, signals a potential retreat of Ethereum's staunchest supporters. Hoffman and co-founder Ryan Sean Adams confirm Bankless is entering a "second era," with Adams stepping back and Hoffman exploring new frontiers. Hoffman sharply criticizes the Ethereum Foundation, stating that ETH's poor price performance cannot be separated from its leadership. He has a history of public dissatisfaction, citing the Foundation's failure to drive market growth and its "endless manifestos." His frustration coincides with ETH/BTC hitting multi-month lows and a significant exodus of senior researchers and executives from the Ethereum Foundation, partly attributed to controversial "loyalty oaths." The article contrasts Ethereum's current predicament—with its Layer-2 narrative discredited and ecosystem stagnant—against what should have been a highlight year in 2026 amid tokenization trends. While a previous surge to near $5,000 was driven by corporate buybacks (DAT热潮), ETH has since fallen over 50%. The core question remains: with fading faith and intense competition, what is Ethereum's next solution? Hoffman's divestment symbolizes a growing disconnect between the community and the ecosystem's direction.

Odaily星球日报1 h fa

Bankless Founder Sells Off ETH, Collective Collapse of Ethereum Faith

Odaily星球日报1 h fa

Trading

Spot
Futures
活动图片