Close Menu
FintechFetch
    FintechFetch
    • Home
    • Fintech
    • Financial Technology
    • Credit Cards
    • Finance
    • Stock Market
    • More
      • Business Startups
      • Blockchain
      • Bitcoin News
      • Cryptocurrency
    FintechFetch
    Home»Bitcoin News»Crypto-Stealing Code Found in XRP Toolkit, Devs Urged to Update
    Bitcoin News

    Crypto-Stealing Code Found in XRP Toolkit, Devs Urged to Update

    FintechFetchBy FintechFetchApril 25, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Well, this one’s a developer’s worst nightmare. The XRP Ledger Foundation just had to clean up a major mess after discovering that a commonly used JavaScript library in the XRP ecosystem had been compromised. The library, called xrpl.js, was hiding a nasty little backdoor that could steal your private keys. The XRP Ledger exploit was traced back to a malicious version of the xrpl.js library, putting thousands of wallets at risk.

    On April 21, blockchain security firm Aikido sounded the alarm. They noticed that someone had uploaded five suspicious versions of xrpl.js to the npm package registry, all signed by an unknown publisher going by the name “mukulljangid.” Weirdest part? These versions didn’t exist on the library’s official GitHub, which was a huge red flag.

    We have discovered a backdoor in the official #xrpl NPM package. This back door steals private keys and sends them to attackers. The affected versions 4.2.1 – 4.2.4, if you are using an earlier version, do not upgrade.#crypto #malware #npm pic.twitter.com/wshcTFKjbR

    — Aikido Security (@AikidoSecurity) April 22, 2025

    Digging into the code, Aikido found a function called checkValidityOfSeed hidden inside the wallet creation process. It was doing one thing, quietly sending private keys off to an outside domain called 0x9c.xyz. In short, any app using one of those versions could have leaked users’ wallet credentials without them ever knowing.

    The XRP Ledger Foundation acted fast. They pulled the infected versions from npm and pushed out a clean one, version 4.2.5. Developers were told to upgrade immediately to shut the door on the exploit.

    The Impact of this Discovered Exploit

    This wasn’t just a small blip either. xrpl.js is a big part of the XRP developer toolkit, clocking over 140,000 downloads a week. That means any project that integrated one of the malicious versions could have unknowingly put users at risk.

    –
    Price
    Market Cap
    –
    –
    –





    DISCOVER: 9+ Best High-Risk, High–Reward Crypto to Buy in March 2025

    Luckily, not everyone was affected. Established platforms in the XRP ecosystem like XRPScan, First Ledger, and Gen3 Games said they were in the clear. Still, the fact that a compromised version of the core library got published and downloaded is a serious reminder of just how fragile software supply chains can be.

    Even with the scare, XRP’s market price didn’t flinch. The token actually ended the day up more than 3.5 percent, sitting pretty with a market cap north of $125 billion. So while the devs were scrambling behind the scenes, the market didn’t seem too spooked.

    XRP Ledger Exploit: Security Recommendations

    If you’re a developer working with xrpl.js, here’s the quick checklist:

    • Update immediately to version 4.2.5 or roll back to 2.14.3, which was not affected
    • If there’s any chance a compromised version touched your environment, rotate your private keys
    • Use lockfiles to avoid surprise updates sneaking into your build
    • Be cautious with versioning symbols like ^ in your package.json since they can silently pull in minor updates

    Conclusion

    This incident is a textbook example of a supply chain attack and shows how even trusted libraries can become attack vectors. With crypto, the stakes are high and the window for error is small. If you’re building in this space, staying paranoid might just save your project, and your users’ funds.

    DISCOVER: 20+ Next Crypto to Explode in 2025 

    Join The 99Bitcoins News Discord Here For The Latest Market Updates

    • Malicious versions of the popular XRP developer library xrpl.js were uploaded to npm, containing code that leaked private keys.
    • The rogue versions were not present on the library’s official GitHub, and were flagged by security firm Aikido on April 21.
    • The XRP Ledger Foundation responded quickly, removing the infected packages and releasing a clean update (v4.2.5).
    • Projects using compromised versions could have exposed users to wallet breaches; developers are urged to update and rotate keys.
    • The incident highlights major risks in crypto software supply chains, even as XRP’s market price remained unaffected.

    The post Crypto-Stealing Code Found in XRP Toolkit, Devs Urged to Update appeared first on 99Bitcoins.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSaison Capital, BRI Ventures & Coinvestasi Launches Tokenize Indonesia
    Next Article Sales of Small Businesses Surged in Q1, Per New Report
    FintechFetch
    • Website

    Related Posts

    Bitcoin News

    Iran Response to US Bombing: Bitcoin Recovers As WW3 Looms

    June 22, 2025
    Bitcoin News

    Why is The US Market Closed Today? What is Juneteenth National Independence Day?

    June 21, 2025
    Bitcoin News

    UK to Cap Bank Crypto Holdings at 1 Percent by 2026

    June 21, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Up 100% in a year, this FTSE 100 stock is just warming up

    March 8, 2025

    At $184, I reckon this S&P 500 juggernaut is still on sale

    April 14, 2025

    Best Wallet Presale Races Past $11M as It Receives Analyst Endorsement

    March 20, 2025

    How I Built Resilience While Facing Divorce and Heartbreak

    May 3, 2025

    Marqeta and Klarna Extend Partnership to Roll Out the Klarna Card in the US

    June 15, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Business Startups
    • Credit Cards
    • Cryptocurrency
    • Finance
    • Financial Technology
    • Fintech
    • Stock Market
    Most Popular

    Flutterwave Secures Approval From Bank of Ghana to Provide Remittance Services

    March 14, 2025

    Dogecoin Chart Too Good To Ignore, Says Trader Eyeing Double

    May 20, 2025

    The Stock Market Imploded, But This OpenAI Tool Sees It as Opportunity

    April 13, 2025
    Our Picks

    Bitcoin Closes Daily Price Below 50MA

    June 22, 2025

    Etraveli Group Selects Mastercard to Improve Its Fintech Arm’s Product, PRECISION

    June 22, 2025

    Using AI in Customer Service? Don’t Make These 4 Mistakes

    June 22, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Business Startups
    • Credit Cards
    • Cryptocurrency
    • Finance
    • Financial Technology
    • Fintech
    • Stock Market
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2024 Fintechfetch.comAll Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.