Altcoins News

Story: XRP Security Breach Exposes Private Keys in xrpl.js Attack

By Steven Anderson

1 / 9

In a concerning development for the XRP ecosystem, Ripple’s widely-used JavaScript library, xrpl.

2 / 9

The attack specifically targeted the xrpl.js package distributed via the Node Package Manager (NPM), where certain versions—namely 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.

3 / 9

Notably, major services in the XRP ecosystem, such as Xaman Wallet and XRPScan, have confirmed they were not impacted by the compromised versions, offering some relief to users.

4 / 9

Peter Todd, a respected Bitcoin developer and vocal critic of Ripple’s security practices, weighed in on the situation.

5 / 9

The attacker responsible for the breach operated under the npm username “mukulljangid” and reportedly gained access via a compromised Ripple employee’s account.

6 / 9

In response, the XRP Ledger Foundation has confirmed that all compromised versions of xrpl.js have been taken down from official channels.

7 / 9

This breach has once again thrown a spotlight on the fragile state of software security within the cryptocurrency industry.

8 / 9

The XRP price has already felt the weight of this news, currently trading around $2.18 after a 4.43% drop.

9 / 9

In conclusion, while Ripple’s swift acknowledgment and patching of the issue may have limited the damage, the breach serves as a harsh reminder that in crypto, even a single…

The Currency Analytics

Want the full story?