• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home News

XRP Ledger Bug Patched After 'Serious' Flaw Spotted in XRPL Library

admin by admin
April 25, 2025
in News
0
XRP Ledger Bug Patched After 'Serious' Flaw Spotted in XRPL Library
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



A threat actor seemingly exploited an XRP Ledger’s developer access token to publish illicit code to the burgeoning network in a move that could have been “catastrophic” for the network, the security team that spotted the issue said in an update.

Related articles

Swedish health firm jumps 37% on first Bitcoin buy, China EV seller to buy 1K BTC

Swedish health firm jumps 37% on first Bitcoin buy, China EV seller to buy 1K BTC

May 23, 2025
‘No questions asked’ Bitcoin launderer gets 6 years in prison

‘No questions asked’ Bitcoin launderer gets 6 years in prison

May 23, 2025

Charlie Eriksen, a researcher at Aikido Security who first spotted the problem, said a hidden issue was added to recent versions of a new toolkit used to build apps that work with the XRP Ledger.

“A developer's NPM access token was stolen by the threat actors,” Aikido said on X. “It is unclear how right now. It is also unclear who the threat actors are right now (although we have a hunch we are trying to confirm).”

The issue only affects versions of Node Package Manager (NPM), a site where developers share reusable code for projects. Major XRP-related services, like Xaman Wallet and XRPScan, said they were unaffected in separate X posts.

This flaw could let attackers steal users’ private keys, possibly accessing their crypto wallets in theory.

“At 21 Apr, 20:53 GMT+0, our system, Aikido Intel started to alert us to five new package version of the xrpl package. It is the official SDK for the XRP Ledger, with more than 140.000 weekly downloads,” Eriksen said in a security update.

“This package is used by hundreds of thousands of applications and websites making it a potentially catastrophic supply chain attack on the cryptocurrency ecosystem,” Eriksen noted.

He added that only third-party apps or services that installed the flawed versions during a brief period could be at risk.

As such, the XRP Ledger Foundation team quickly fixed the issue by releasing updated versions of the tool to replace the faulty ones. The affected versions (v4.2.1-4.2.4 and v2.14.2) were deprecated.

“To clarify: This vulnerability is in xrpl.js, a JavaScript library for interacting with the XRP Ledger. It does NOT affect the XRP Ledger codebase or Github repository itself. Projects using xrpl.js should upgrade to v4.2.5 immediately,” the foundation posted separately.

A JavaScript library is a collection of pre-written code to simplify tasks in web development. A GitHub repo is an online storage space for a project's code, files, and history, hosted on GitHub.

XRP prices are up 8.5% in the past 24 hours alongside a broader market jump.



#XRP #Ledger #Bug #Patched #039Serious039 #Flaw #Spotted #XRPL #Library

Tags: 039Serious039a drop in bitcoin s valueaccounting for 348 coin atm radaraikido intelbitcoin s correction belowBugbull market trader sees 70k btcchain attack on the cryptocurrency ecosystemcrypto exchange okx fined 1crypto leaders hide behind blockchain scrypto walletdownload a separate privacy wallet pFlawfried are hopefulinauguration meanwhile avax has slippedinvestor sentiment the companyis adoption will accelerate but 2025is used by hundreds of thousandsits zkevm network which has processedLedgerLibraryold ceasefire thousands of people havePatcheds developer accessSpottedtanzanias main opposition chadema party barredthe xrp ledger codebaseto em politico em theto his company to the stocktoken was stolen by the threatXRPXRPL
Share76Tweet47

Related Posts

Swedish health firm jumps 37% on first Bitcoin buy, China EV seller to buy 1K BTC

Swedish health firm jumps 37% on first Bitcoin buy, China EV seller to buy 1K BTC

by admin
May 23, 2025
0

Shares in Swedish health tech company H100 Group AB rose 37% after it said it purchased Bitcoin for the first...

‘No questions asked’ Bitcoin launderer gets 6 years in prison

‘No questions asked’ Bitcoin launderer gets 6 years in prison

by admin
May 23, 2025
0

A US man operating what prosecutors called a “no questions asked” cash-to-Bitcoin conversion service has been sentenced to six years...

Bitcoin could go much higher due to lack of FOMO and futures market euphoria — Analysts

Bitcoin could go much higher due to lack of FOMO and futures market euphoria — Analysts

by admin
May 23, 2025
0

Key takeaways:Bitcoin’s rally to new price highs happened as funding rates and trading sentiment remained unusually subdued.Rising stablecoin supply and...

Michigan lawmakers file 4 crypto bills on retiree funds, CBDCs, mining

Michigan lawmakers file 4 crypto bills on retiree funds, CBDCs, mining

by admin
May 23, 2025
0

Michigan lawmakers have introduced four crypto-related bills covering crypto mining, central bank digital currencies (CBDCs) and crypto in state retirement...

Solana price fractal targets rally to 0, but one thing must happen first — Analysts

Solana price fractal targets rally to $260, but one thing must happen first — Analysts

by admin
May 23, 2025
0

Key takeaways:After briefly dropping to $160 from $184, Solana (SOL) is attempting to reclaim a position above its key resistance...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Swedish health firm jumps 37% on first Bitcoin buy, China EV seller to buy 1K BTC

Swedish health firm jumps 37% on first Bitcoin buy, China EV seller to buy 1K BTC

May 23, 2025
‘No questions asked’ Bitcoin launderer gets 6 years in prison

‘No questions asked’ Bitcoin launderer gets 6 years in prison

May 23, 2025
Bitcoin could go much higher due to lack of FOMO and futures market euphoria — Analysts

Bitcoin could go much higher due to lack of FOMO and futures market euphoria — Analysts

May 23, 2025
Michigan lawmakers file 4 crypto bills on retiree funds, CBDCs, mining

Michigan lawmakers file 4 crypto bills on retiree funds, CBDCs, mining

May 23, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com