Monday, November 17, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

XRP Ledger Compromised? Validator Warns Projects And Developers Of Critical Issues

by DigestWire member
April 23, 2025
in Blockchain, Crypto Market, Cryptocurrency
0
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

An XRP Ledger (XRPL) validator has warned projects and developers that the network is compromised. He revealed some critical issues on the network, which put users and their funds at risk of an exploit. 

Validator Warns That XRP Ledger is Compromised

In an X post, XRP Ledger validator Vet told the network’s developers and projects that use the XRPL js library not to update or use any version 4.2.1 or higher, as it has been compromised. He remarked that any project utilizing the newest version of XRPL is putting users and funds at risk of an attack from hackers. 

Vet’s warning was in response to a post by Aikido Security, in which they stated that they had discovered a backdoor in the official XRP Ledger NPM package. The blockchain security firm added that this back door steals private keys and sends them to attackers. The affected versions are 4.2.1 and 4.2.4, so developers and projects should not upgrade to these versions. 

Ripple Chief Technology Officer (CTO) David Schwartz also commented on the Ledger situation, noting that it was just the XRPL.js from NPM that was compromised. He also alluded to a post by Ripple senior software engineer Mayukha Vadari. Vadari mentioned that the Ledger itself is unaffected by the malware. 

The engineer confirmed that the malware packages only affected services that use xrpl.js and were upgraded to the malicious versions that were published about a day ago. He added that GitHub remains safe, as only npm has been compromised. Vadari urged users to avoid services that have access to their private keys and seed phrases until they have confirmed that these services are unaffected by this malware. 

XRPL Foundation Provides Update 

The XRP Ledger Foundation also provided an update on the malware situation. In an X post, the Foundation clarified that the vulnerability is in xrpl.js, a JavaScript library for interacting with the XRPL. They further stated that the vulnerability does not affect the network’s codebase or the GitHub repository itself. Meanwhile, the Foundation urged projects using xrpl.js to upgrade to v4.2.5 immediately. 

The XRP Ledger Foundation also confirmed in the thread that it had deprecated the compromised xrpl.js versions on npm. They mentioned that they will share a detailed post-mortem soon and again urged projects and developers to ensure that they are using versions 4.2.5 or 2.14.3. 

In another X post, the Foundation announced that it has published an updated npm package for users of the 2.14.x branch to remove the previously compromised version. They asked these XRP Ledger users to update immediately to version 2.14.3 to prevent an attack. 

XRP

Read Entire Article
Tags: BitcoinistBlockchainCoin Surges
Share30Tweet19
Next Post
Other Nepo Babies Might Want To Take Note After Bryce Dallas Howard Delivered A Masterclass In How To Acknowledge Your Privilege

Other Nepo Babies Might Want To Take Note After Bryce Dallas Howard Delivered A Masterclass In How To Acknowledge Your Privilege

XRP Targets $33 To $50 By September 2027, Research Firm Says

Birmingham bin strike resolution ‘could be in touching distance’ – as conciliation service drafted in

Birmingham bin strike resolution 'could be in touching distance' - as conciliation service drafted in

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Bone AI raises $12M to challenge Asia’s defense giants with AI-powered robotics

Morning Update: What you need to know in Maine today

There’s an issue that people in big cities and rural areas agree on, according to a new poll

Former Republican lawmaker takes step toward running for Maine governor

Capitol agenda: Trump blinks on Epstein as GOP rebels

Inquest into death of baby killed in XL bully attack opens

Trending

Lions: Dan Campbell defends Rock Ya-Sin after ‘absolutely terrible’ pass interference penalty
Football

Lions: Dan Campbell defends Rock Ya-Sin after ‘absolutely terrible’ pass interference penalty

by DigestWire member
November 17, 2025
0

The Detroit Lions fell to 6-4 after a defeat to the Philadelphia Eagles that came with a...

Scotland v Denmark: Line-ups, stats and preview

Scotland v Denmark: Line-ups, stats and preview

November 17, 2025
Joaquin Phoenix, Rooney Mara Board Cannes-Winning Palestinian Short ‘I’m Glad You’re Dead Now’ as Executive Producers (EXCLUSIVE)

Joaquin Phoenix, Rooney Mara Board Cannes-Winning Palestinian Short ‘I’m Glad You’re Dead Now’ as Executive Producers (EXCLUSIVE)

November 17, 2025
Bone AI raises $12M to challenge Asia’s defense giants with AI-powered robotics

Bone AI raises $12M to challenge Asia’s defense giants with AI-powered robotics

November 17, 2025
Morning Update: What you need to know in Maine today

Morning Update: What you need to know in Maine today

November 17, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Lions: Dan Campbell defends Rock Ya-Sin after ‘absolutely terrible’ pass interference penalty November 17, 2025
  • Scotland v Denmark: Line-ups, stats and preview November 17, 2025
  • Joaquin Phoenix, Rooney Mara Board Cannes-Winning Palestinian Short ‘I’m Glad You’re Dead Now’ as Executive Producers (EXCLUSIVE) November 17, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.