CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
    • Spanish
    • Turkish
    • German
    • Bulgarian
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • CryptoPotato Spanish
  • CryptoPotato Turkey
  • CryptoPotato Germany
  • CryptoPotato Bulgaria
  • Market Updates
  • BTC Analysis
  • ETH Analysis
  • XRP Analysis
  • Interviews
CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
    • Spanish
    • Turkish
    • German
    • Bulgarian
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • CryptoPotato Spanish
  • CryptoPotato Turkey
  • CryptoPotato Germany
  • CryptoPotato Bulgaria
Home » Crypto News » XRP Ledger SDK Compromised by Backdoor Exploit

XRP Ledger SDK Compromised by Backdoor Exploit

Author: Wayne Jones

Last Updated Apr 23, 2025 @ 13:25

A critical security flaw was discovered in XRPL’s JavaScript toolkit, with some versions modified to steal private keys.

Getting your audio player ready...

The XRP Ledger Foundation has warned about a security vulnerability in the official JavaScript SDK, which interacts with the XRPL.

On April 21, Aikido Security revealed that several versions of its Node Package Manager (NPM) software were compromised and published, containing a backdoor that could steal private keys from users.

Security Flaw in Developer Kit

The XRP Ledger Foundation confirmed the issue in an April 22 statement:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1-4.2.4 and v2.14.2).”

In response to the breach, Wietse Wind, founder and CEO of XRPL Labs, reassured users that Xaman Wallet was not affected by the flaw. Wind explained that the product does not use xrpl.js but instead relies on its xrpl-client and xrpl-accountlib libraries, which separate wallet connectivity from the signing process.

He also detailed how the incident unfolded, stating that malicious code in the xrpl.js package sent generated or imported private keys to an external server controlled by the attacker. This enabled hackers to collect key pairs, wait for the wallets to be funded, and then steal the assets.

Wind urged anyone who had recently created an XRP wallet using the API or related tools to assume it had been compromised and to transfer their funds immediately.

He emphasized that such attacks can happen to any software relying on third-party libraries, and that developers must take precautions. He also advised limiting publishing access, scanning code before release, avoiding auto-publishing pipelines, and not managing private keys directly unless fully prepared to handle the associated risks.

XRPL Issues Urgent Patch

Following the incident, the XRP Ledger Foundation has released a clean version of the NPM package, removing the malicious code and ensuring the SDK is safe for developers to use again.

Aikido Security discovered the vulnerability after its automated threat monitoring system flagged suspicious updates to the XRPL package on NPM. These updates, published by a user named “mukulljangid”, included five new versions that did not match any official releases on the XRP Ledger’s GitHub repository.

After investigating, Aikido found that the compromised versions contained a malicious function called checkValidityOfSeed, which sent private keys to the hacker’s server at 0x9c[.]xyz, when users created a wallet that could allow them to steal their crypto.

Early versions (v4.2.1 and v4.2.2) hid the backdoor in compiled JavaScript files, while later versions (v4.2.3 and v4.2.4) embedded the malicious code directly in TypeScript source files, making it harder to detect. The compromised packages also removed development tools like Prettier and build scripts from the package.json file, showing intentional manipulation.

The incident comes only weeks after Ripple announced a $1.25 billion acquisition of prime brokerage firm Hidden Road, a move experts believe will turn XRPL into a major conduit for institutional funds.

According to Ripple CEO Brad Garlinghouse, the network will be used for post-trade settlements on some transactions, potentially turning it into a corporate-scale clearing and credit platform.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Tags: Crypto Wallets Hacking XRP
Enjoy reading? Share with your friends
Facebook Twitter LinkedIn Telegram

About The Author

Wayne Jones
More posts by this author

Wayne is a dynamic part-time trader with an impressive eye for detail. His passion for understanding financial systems has led to an intriguing interest in blockchain technology, and he enjoys exploring and writing about cryptocurrencies. Possessing a keen intellect and diligent work ethic, he stays up-to-date on the latest industry trends, regularly sharing his insights in articles and professional presentations.

Join Our Community

FacebookX YouTubeTelegram


Editorials
5 Best Meme Coin Presales to Watch in May 2025

5 Best Meme Coin Presales to Watch in May 2025

Toobit Review 2025: Is Toobit a Safe Crypto Exchange?

Toobit Review 2025: Is Toobit a Safe Crypto Exchange?

Hyperliquid Bridge: How to Bridge USDC to Hyperliquid

Hyperliquid Bridge: How to Bridge USDC to Hyperliquid

11 Best Crypto Presales to Consider in May 2025

11 Best Crypto Presales to Consider in May 2025

Need for Speed – Only Ultra-Fast Blockchains Will Win the Adoption Race (Opinion)

Need for Speed – Only Ultra-Fast Blockchains Will Win the Adoption Race (Opinion)

The 5 Best Bitcoin Mining Pools in 2025: Complete Guide

The 5 Best Bitcoin Mining Pools in 2025: Complete Guide

The 5 Best Crypto Staking Platforms in 2025: Everything You Need to Know

The 5 Best Crypto Staking Platforms in 2025: Everything You Need to Know

Join Our Newsletter
Become a CryptoPotato VIP
One Weekly Email Can Change Your Crypto Life.
Sign-up FREE to receive our extended weekly market update and coin analysis report
We NEVER send spam. You can unsubscribe at any time.
Invalid email address
Thanks for subscribing!
Footer Logo
About
Advertise on CryptoPotato
About Us | Contact Us | Careers
Editorial Policy
Terms of service | Privacy Policy | GDPR
More Sections
IEO List | Evaluations
Airdrops
Scholarship
Disclaimer
Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. Full disclaimer
© Copyright CryptoPotato 2016 - 2025
Scroll to top
One Daily Email Can Change Your Crypto Life.

Sign-up FREE to receive our extended daily market update and coin analysis report

We never send SPAM. You can unsubscribe at any moment
Invalid email address
Thanks for subscribing!