Close Menu
FintechFetch
    FintechFetch
    • Home
    • Fintech
    • Financial Technology
    • Credit Cards
    • Finance
    • Stock Market
    • More
      • Business Startups
      • Blockchain
      • Bitcoin News
      • Cryptocurrency
    FintechFetch
    Home»Bitcoin News»Crypto-Stealing Code Found in XRP Toolkit, Devs Urged to Update
    Bitcoin News

    Crypto-Stealing Code Found in XRP Toolkit, Devs Urged to Update

    FintechFetchBy FintechFetchApril 25, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Well, this one’s a developer’s worst nightmare. The XRP Ledger Foundation just had to clean up a major mess after discovering that a commonly used JavaScript library in the XRP ecosystem had been compromised. The library, called xrpl.js, was hiding a nasty little backdoor that could steal your private keys. The XRP Ledger exploit was traced back to a malicious version of the xrpl.js library, putting thousands of wallets at risk.

    On April 21, blockchain security firm Aikido sounded the alarm. They noticed that someone had uploaded five suspicious versions of xrpl.js to the npm package registry, all signed by an unknown publisher going by the name “mukulljangid.” Weirdest part? These versions didn’t exist on the library’s official GitHub, which was a huge red flag.

    We have discovered a backdoor in the official #xrpl NPM package. This back door steals private keys and sends them to attackers. The affected versions 4.2.1 – 4.2.4, if you are using an earlier version, do not upgrade.#crypto #malware #npm pic.twitter.com/wshcTFKjbR

    — Aikido Security (@AikidoSecurity) April 22, 2025

    Digging into the code, Aikido found a function called checkValidityOfSeed hidden inside the wallet creation process. It was doing one thing, quietly sending private keys off to an outside domain called 0x9c.xyz. In short, any app using one of those versions could have leaked users’ wallet credentials without them ever knowing.

    The XRP Ledger Foundation acted fast. They pulled the infected versions from npm and pushed out a clean one, version 4.2.5. Developers were told to upgrade immediately to shut the door on the exploit.

    The Impact of this Discovered Exploit

    This wasn’t just a small blip either. xrpl.js is a big part of the XRP developer toolkit, clocking over 140,000 downloads a week. That means any project that integrated one of the malicious versions could have unknowingly put users at risk.

    –
    Price
    Market Cap
    –
    –
    –





    DISCOVER: 9+ Best High-Risk, High–Reward Crypto to Buy in March 2025

    Luckily, not everyone was affected. Established platforms in the XRP ecosystem like XRPScan, First Ledger, and Gen3 Games said they were in the clear. Still, the fact that a compromised version of the core library got published and downloaded is a serious reminder of just how fragile software supply chains can be.

    Even with the scare, XRP’s market price didn’t flinch. The token actually ended the day up more than 3.5 percent, sitting pretty with a market cap north of $125 billion. So while the devs were scrambling behind the scenes, the market didn’t seem too spooked.

    XRP Ledger Exploit: Security Recommendations

    If you’re a developer working with xrpl.js, here’s the quick checklist:

    • Update immediately to version 4.2.5 or roll back to 2.14.3, which was not affected
    • If there’s any chance a compromised version touched your environment, rotate your private keys
    • Use lockfiles to avoid surprise updates sneaking into your build
    • Be cautious with versioning symbols like ^ in your package.json since they can silently pull in minor updates

    Conclusion

    This incident is a textbook example of a supply chain attack and shows how even trusted libraries can become attack vectors. With crypto, the stakes are high and the window for error is small. If you’re building in this space, staying paranoid might just save your project, and your users’ funds.

    DISCOVER: 20+ Next Crypto to Explode in 2025 

    Join The 99Bitcoins News Discord Here For The Latest Market Updates

    • Malicious versions of the popular XRP developer library xrpl.js were uploaded to npm, containing code that leaked private keys.
    • The rogue versions were not present on the library’s official GitHub, and were flagged by security firm Aikido on April 21.
    • The XRP Ledger Foundation responded quickly, removing the infected packages and releasing a clean update (v4.2.5).
    • Projects using compromised versions could have exposed users to wallet breaches; developers are urged to update and rotate keys.
    • The incident highlights major risks in crypto software supply chains, even as XRP’s market price remained unaffected.

    The post Crypto-Stealing Code Found in XRP Toolkit, Devs Urged to Update appeared first on 99Bitcoins.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSaison Capital, BRI Ventures & Coinvestasi Launches Tokenize Indonesia
    Next Article Sales of Small Businesses Surged in Q1, Per New Report
    FintechFetch
    • Website

    Related Posts

    Bitcoin News

    Ripple Warns Senate: The New Crypto Bill Could Enable SEC “Overreach”

    August 7, 2025
    Bitcoin News

    What is Talos AI Agent? Why is T Crypto Exploding? Best Crypto to Buy Now?

    August 7, 2025
    Bitcoin News

    Cardano Is Cooking: Sleeping on ADA Price Prediction Could Be Your Biggest Mistake in 2025

    August 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Business Advice: I Asked 100+ Founders of $1M-$1B Businesses

    February 26, 2025

    The Shell share price is down 16% in April and looks a bargain to me

    April 15, 2025

    Cali BBQ’s Recipe for Authentic Engagement

    February 9, 2025

    Automate Your Job Search and Get More Interviews for Only $40

    February 15, 2025

    From Presence to Performance: Rethinking LinkedIn for Business Growth

    April 10, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Business Startups
    • Credit Cards
    • Cryptocurrency
    • Finance
    • Financial Technology
    • Fintech
    • Stock Market
    Most Popular

    Jarvis Launches Free Salary Sacrifice Calculator to Help Firms Improve Pensions Amid Tough Economies

    March 21, 2025

    Ria Money Transfer Sets Sights on Supporting Businesses in Malaysia to Manage Worker Wages

    June 16, 2025

    Ramaswamy’s Strive Targets 75,000 BTC in Mt. Gox Windfall

    May 22, 2025
    Our Picks

    Spot Ethereum ETFs Are Bleeding With Record Outflows, ETH Price To Crash Below $3,000?

    August 7, 2025

    CRA prevails over Holt Renfrew saleswoman in battle over wardrobe deduction

    August 7, 2025

    When Crypto Turns Violent: The Rise of Wrench Attacks

    August 7, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Business Startups
    • Credit Cards
    • Cryptocurrency
    • Finance
    • Financial Technology
    • Fintech
    • Stock Market
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2024 Fintechfetch.comAll Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.