• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home News

XRP Ledger Bug Patched After 'Serious' Flaw Spotted in XRPL Library

admin by admin
April 25, 2025
in News
0
XRP Ledger Bug Patched After 'Serious' Flaw Spotted in XRPL Library
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



A threat actor seemingly exploited an XRP Ledger’s developer access token to publish illicit code to the burgeoning network in a move that could have been “catastrophic” for the network, the security team that spotted the issue said in an update.

Related articles

Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

May 28, 2025
Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

May 28, 2025

Charlie Eriksen, a researcher at Aikido Security who first spotted the problem, said a hidden issue was added to recent versions of a new toolkit used to build apps that work with the XRP Ledger.

“A developer's NPM access token was stolen by the threat actors,” Aikido said on X. “It is unclear how right now. It is also unclear who the threat actors are right now (although we have a hunch we are trying to confirm).”

The issue only affects versions of Node Package Manager (NPM), a site where developers share reusable code for projects. Major XRP-related services, like Xaman Wallet and XRPScan, said they were unaffected in separate X posts.

This flaw could let attackers steal users’ private keys, possibly accessing their crypto wallets in theory.

“At 21 Apr, 20:53 GMT+0, our system, Aikido Intel started to alert us to five new package version of the xrpl package. It is the official SDK for the XRP Ledger, with more than 140.000 weekly downloads,” Eriksen said in a security update.

“This package is used by hundreds of thousands of applications and websites making it a potentially catastrophic supply chain attack on the cryptocurrency ecosystem,” Eriksen noted.

He added that only third-party apps or services that installed the flawed versions during a brief period could be at risk.

As such, the XRP Ledger Foundation team quickly fixed the issue by releasing updated versions of the tool to replace the faulty ones. The affected versions (v4.2.1-4.2.4 and v2.14.2) were deprecated.

“To clarify: This vulnerability is in xrpl.js, a JavaScript library for interacting with the XRP Ledger. It does NOT affect the XRP Ledger codebase or Github repository itself. Projects using xrpl.js should upgrade to v4.2.5 immediately,” the foundation posted separately.

A JavaScript library is a collection of pre-written code to simplify tasks in web development. A GitHub repo is an online storage space for a project's code, files, and history, hosted on GitHub.

XRP prices are up 8.5% in the past 24 hours alongside a broader market jump.



#XRP #Ledger #Bug #Patched #039Serious039 #Flaw #Spotted #XRPL #Library

Tags: 039Serious039a drop in bitcoin s valueaccounting for 348 coin atm radaraikido intelbitcoin s correction belowBugbull market trader sees 70k btcchain attack on the cryptocurrency ecosystemcrypto exchange okx fined 1crypto leaders hide behind blockchain scrypto walletdownload a separate privacy wallet pFlawfried are hopefulinauguration meanwhile avax has slippedinvestor sentiment the companyis adoption will accelerate but 2025is used by hundreds of thousandsits zkevm network which has processedLedgerLibraryold ceasefire thousands of people havePatcheds developer accessSpottedtanzanias main opposition chadema party barredthe xrp ledger codebaseto em politico em theto his company to the stocktoken was stolen by the threatXRPXRPL
Share76Tweet47

Related Posts

Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

by admin
May 28, 2025
0

White House AI and crypto czar David Sacks says the US could buy more Bitcoin if the government can fund...

Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

by admin
May 28, 2025
0

Bitcoin held steady near $109,000 early Wednesday as traders bet on fresh highs in the coming months, with ether rising...

CFTC’s Goldsmith Romero says commissioner exodus ‘not a great situation’

CFTC’s Goldsmith Romero says commissioner exodus ‘not a great situation’

by admin
May 28, 2025
0

Outgoing US Commodity Futures Trading Commission commissioner Christy Goldsmith Romero says the exodus of the agency’s top brass is “not...

Trump’s CFTC pick Quintenz discloses crypto links, .4M assets

Trump’s CFTC pick Quintenz discloses crypto links, $3.4M assets

by admin
May 28, 2025
0

US President Donald Trump’s pick to chair the Commodity Futures Trading Commission has disclosed millions of dollars worth of assets,...

Bitcoin’s ‘aggressive leg higher’ in Q3 still up in the air: Analyst

Bitcoin’s ‘aggressive leg higher’ in Q3 still up in the air: Analyst

by admin
May 28, 2025
0

Bitcoin’s recent all-time high of $111,970 has sparked optimism among crypto market participants, but whether that carries through into the...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
ASIC Sues Former Blockchain Global Exec Over M in Unpaid Customer Claims

ASIC Sues Former Blockchain Global Exec Over $20M in Unpaid Customer Claims

May 28, 2025
Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

May 28, 2025
Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

May 28, 2025
Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

May 28, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com