XRP Ledger Compromised? Validator Warns Projects And Developers Of Critical Issues

bitcoinistPublicado em 2025-04-23Última atualização em 2025-04-23

Resumo

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues on the network, which put users and their funds at risk of an exploit. 

Validator Warns That XRP Ledger is Compromised

In an X post, XRP Ledger validator Vet told the network’s developers and projects that use the XRPL js library not to update or use any version 4.2.1 or higher, as it has been compromised. He remarked that any project utilizing the newest version of XRPL is putting users and funds at risk of an attack from hackers. 

Vet’s warning was in response to a post by Aikido Security, in which they stated that they had discovered a backdoor in the official XRP Ledger NPM package. The blockchain security firm added that this back door steals private keys and sends them to attackers. The affected versions are 4.2.1 and 4.2.4, so developers and projects should not upgrade to these versions. 

Ripple Chief Technology Officer (CTO) David Schwartz also commented on the Ledger situation, noting that it was just the XRPL.js from NPM that was compromised. He also alluded to a post by Ripple senior software engineer Mayukha Vadari. Vadari mentioned that the Ledger itself is unaffected by the malware. 

The engineer confirmed that the malware packages only affected services that use xrpl.js and were upgraded to the malicious versions that were published about a day ago. He added that GitHub remains safe, as only npm has been compromised. Vadari urged users to avoid services that have access to their private keys and seed phrases until they have confirmed that these services are unaffected by this malware. 

XRPL Foundation Provides Update 

The XRP Ledger Foundation also provided an update on the malware situation. In an X post, the Foundation clarified that the vulnerability is in xrpl.js, a JavaScript library for interacting with the XRPL. They further stated that the vulnerability does not affect the network’s codebase or the GitHub repository itself. Meanwhile, the Foundation urged projects using xrpl.js to upgrade to v4.2.5 immediately. 

The XRP Ledger Foundation also confirmed in the thread that it had deprecated the compromised xrpl.js versions on npm. They mentioned that they will share a detailed post-mortem soon and again urged projects and developers to ensure that they are using versions 4.2.5 or 2.14.3. 

In another X post, the Foundation announced that it has published an updated npm package for users of the 2.14.x branch to remove the previously compromised version. They asked these XRP Ledger users to update immediately to version 2.14.3 to prevent an attack. 

XRP
XRP trading at $2.2 on the 1D chart | Source: XRPUSDT on Tradingview.com
Featured image from YouTube, chart from Tradingview.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Scott Matherson is a leading crypto writer at Bitcoinist, who possesses a sharp analytical mind and a deep understanding of the digital currency landscape. Scott has earned a reputation for delivering thought-provoking and well-researched articles that resonate with both newcomers and seasoned crypto enthusiasts. Outside of his writing, Scott is passionate about promoting crypto literacy and often works to educate the public on the potential of blockchain.

Leituras Relacionadas

Dialogue with Xie Jiayin: I Have Ambition, and So Does Bitget

In a candid interview, Xie Jiayin, the Head of Greater China at Bitget, discusses his ambitious vision for the exchange and its rapid growth. Since joining in early 2024, Xie has championed a user-centric approach, aiming to build "the warmest exchange." Under his leadership, Bitget has expanded its user base to over 120 million, with monthly trading volume reaching $750 billion, making it a top-three exchange in the Chinese-speaking market. Xie emphasizes the importance of direct engagement, often working 12-14 hours daily and maintaining an active presence on social media, where he has posted over 17,000 tweets and replies. He insists on swift responses from his team to user inquiries, reflecting Bitget’s commitment to accountability and trust. Bitget’s strategy includes innovative products like UEX (Universal Exchange), offering traditional assets such as U.S. stocks, gold, and forex contracts. The platform recently became the first to achieve $10 billion in U.S. stock contract trading volume. Xie acknowledges the competitive landscape but remains confident in Bitget’s growth, targeting a monthly trading volume of $1 trillion by 2026. He also highlights Bitget’s philanthropic efforts, including a $12 million donation for disaster relief in Hong Kong, and the exchange’s focus on institutional and VIP services. Despite market fluctuations, Xie advocates for long-term optimism in crypto, comparing the industry’s current stage to the early internet era and encouraging young talent to join the evolving space. Xie’s personal and professional goals align with Bitget’s ambition: to solidify its position as a top global exchange and continue driving innovation-driven, user-focused growth.

深潮Há 40m

Dialogue with Xie Jiayin: I Have Ambition, and So Does Bitget

深潮Há 40m

Web3 Entrepreneurship in Mainland China: What Can and Cannot Be Done?

Summary: Under China's current legal and regulatory framework, Web3 entrepreneurship is possible but must avoid activities related to issuing tokens, speculative trading, fundraising, or operating exchanges. The article outlines four viable paths: 1. **Pure Technology & Infrastructure**: Developing blockchain as a distributed database or collaborative tool for enterprises and governments, focusing on data verification, supply chain coordination, and judicial record-keeping without financial incentives. 2. **De-Financialized Digital Assets**: Creating non-fungible tokens (NFTs) as digital collectibles, membership passes, or copyright certificates—emphasizing utility over investment value and avoiding secondary market trading. 3. **Compliance & Risk Management Services**: Providing legal, regulatory, and analytical support for Web3 projects, including anti-money laundering measures and chain monitoring, which are increasingly essential as regulations evolve. 4. **Overseas-Centric Operations with Domestic Support**: Structuring projects so that technical development, research, and backend services are handled in mainland China, while financial aspects (e.g., token issuance, trading) are managed by compliant entities abroad. The author stresses that success depends on treating Web3 as a tool rather than a financial instrument, avoiding public promotions of crypto investments, and ensuring clear legal boundaries to sustain long-term operations.

marsbitHá 1h

Web3 Entrepreneurship in Mainland China: What Can and Cannot Be Done?

marsbitHá 1h

Trading

Spot
Futuros
活动图片