Connect with us
  • tg

Cryptocurrency

XRP Ledger SDK Compromised by Backdoor Exploit

letizo News

Published

on

The XRP Ledger Foundation has warned about a security vulnerability in the official JavaScript SDK, which interacts with the XRPL.

On April 21, Aikido Security revealed that several versions of its Node Package Manager (NPM) software were compromised and published, containing a backdoor that could steal private keys from users.

Security Flaw in Developer Kit

The XRP Ledger Foundation confirmed the issue in an April 22 statement:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1-4.2.4 and v2.14.2).”

In response to the breach, Wietse Wind, founder and CEO of XRPL Labs, reassured users that Xaman Wallet was not affected by the flaw. Wind explained that the product does not use xrpl.js but instead relies on its xrpl-client and xrpl-accountlib libraries, which separate wallet connectivity from the signing process.

He also detailed how the incident unfolded, stating that malicious code in the xrpl.js package sent generated or imported private keys to an external server controlled by the attacker. This enabled hackers to collect key pairs, wait for the wallets to be funded, and then steal the assets.

Wind urged anyone who had recently created an XRP wallet using the API or related tools to assume it had been compromised and to transfer their funds immediately.

He emphasized that such attacks can happen to any software relying on third-party libraries, and that developers must take precautions. He also advised limiting publishing access, scanning code before release, avoiding auto-publishing pipelines, and not managing private keys directly unless fully prepared to handle the associated risks.

XRPL Issues Urgent Patch

Following the incident, the XRP Ledger Foundation has released a clean version of the NPM package, removing the malicious code and ensuring the SDK is safe for developers to use again.

Aikido Security discovered the vulnerability after its automated threat monitoring system flagged suspicious updates to the XRPL package on NPM. These updates, published by a user named “mukulljangid”, included five new versions that did not match any official releases on the XRP Ledger’s GitHub repository.

After investigating, Aikido found that the compromised versions contained a malicious function called checkValidityOfSeed, which sent private keys to the hacker’s server at 0x9c[.]xyz, when users created a wallet that could allow them to steal their crypto.

Early versions (v4.2.1 and v4.2.2) hid the backdoor in compiled JavaScript files, while later versions (v4.2.3 and v4.2.4) embedded the malicious code directly in TypeScript source files, making it harder to detect. The compromised packages also removed development tools like Prettier and build scripts from the package.json file, showing intentional manipulation.

The incident comes only weeks after Ripple announced a $1.25 billion acquisition of prime brokerage firm Hidden Road, a move experts believe will turn XRPL into a major conduit for institutional funds.

According to Ripple CEO Brad Garlinghouse, the network will be used for post-trade settlements on some transactions, potentially turning it into a corporate-scale clearing and credit platform.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Cryptocurrency

VeChain Kicksoff $15M StarGate Staking Program After SEC’s Staking Clarity

letizo News

Published

on

Layer 1 blockchain platform, VeChain, is set to launch its $15 million StarGate staking program on July 1. The latest rollout is expected to be one of its largest incentive initiatives amid broader industry interest in staking adoption following SEC guidance.

According to the official press release shared with CryptoPotato, the new program arrives days after the SEC clarified that protocol staking does not constitute a securities offering.

$15M StarGate Staking Program

StarGate introduces direct-from-protocol staking on the VeChainThor blockchain, utilizing NFT technology, which enables holders with as few as 10,000 VET to participate while earning higher rewards under the network’s upgraded Weighted Delegated Proof of Stake system.

The program forms a core part of the VeChain Renaissance roadmap, which is the blockchain’s most significant technical overhaul to date, and features enhanced tokenomics, EVM equivalence, and a reworked staking structure. The primary goal of these features is to make VeChainThor more appealing to developers and institutional participants.

In an effort to drive early adoption, the VeChain Foundation has allocated 5.48 billion VTHO tokens, which are valued at approximately $15 million. This will provide a six-month bonus rewards pool that will boost APY for participants who migrate their nodes or stake VET during the program’s initial phase.

Approved staking tiers will range from the Dawn tier, requiring 10,000 VET, to the Mjolnir X tier, requiring 15.6 million VET. The structure also offers higher yields for larger commitments, while smaller holders will still earn rewards within the new system.

VeChain Applauds SEC Ruling on Staking

The launch comes as ETF issuers and banks weigh staking integrations following the SEC’s landmark decision wherein the agency ruled that protocol staking does not constitute a securities offering, and removed registration requirements for solo, self-custodial, and custodial staking. Applying the Howey test, the SEC found that staking rewards stem from participants’ actions, not others’ efforts.

Responding to this clarification, VeChain CEO and Founder, Sunny Lu, said,

“The SEC’s recent guidance validates what we’ve been building toward: a fully compliant, accessible staking model that treats rewards as compensation for network services rather than investment returns. Our innovative approach of leveraging NFTs to represent participation ensures both simplicity for users and full regulatory alignment.”

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Continue Reading

Cryptocurrency

Hackers Suck at Trading: The Story of How This Fraudster Lost $7M Trading ETH

letizo News

Published

on

An on-chain analytics firm analyzes the losses from a fraudulent wallet.

The beauty of trading on-chain lies in the fact that every transaction is 100% public – that goes for both professional traders, beginners, and, believe it or not – even hackers.

This is the story of a supposed fraudster who lost millions in a bad trade.

Hackers Are Not Savvy Traders

Lookonchain, a popular blockchain analysis firm, noted the activity early this morning on its account on the social media platform X.

The wallet in question, which, according to the analysts is linked to illicit hacking activities, received 12,282 Ethereum (ETH) three months ago, valued at around $23.72 million at that time, and sold it at $1,932 per coin.

Earlier today, the same culprit purchased 4,958 ETH at $2,495, totaling $ 12.37 million.

This results in a de-facto loss of around $6.9 million, as noted by Lookonchain.

It’s Not Just Cybercriminals Out Of Luck

As CryptoPotato reported yesterday, it’s not just bad actors that wind up out of pocket.

We noted two separate instances in which two traders, cumulatively, lost multiple millions on very high-risk, overleveraged trades.

Both were testing their luck with 40x and even 50x leverage, only to see their positions shrink as the markets did not turn in their favor.

One tried one too many times to come on top, and the other one failed to realize a significant profit.

This just goes to show that testing fate can quickly lead to an enormous shortfall, regardless of the trader’s intention and the manner in which the funds used for the transactions were obtained.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Continue Reading

Cryptocurrency

Shiba Inu-Themed Meme Coin Tanks After OKX Says Goodbye: Details

letizo News

Published

on

TL;DR

  • A popular meme coin within SHIB’s ecosystem nosedived by double digits after OKX withdrew its support.
  • Team member LUCIE addressed the panic, urging users to embrace DeFi over centralized platforms and warning that even major exchanges aren’t immune to collapse.

BONE Heads South

Shiba Inu (SHIB) is a meme coin that has evolved into a robust ecosystem over the past few years. One of the most popular tokens within the network is Bone ShibaSwap (BONE).

The asset has not been in its best shape lately, posting a 32% decline on a monthly scale and plunging by 12% in the past 24 hours alone.

BONE Price
BONE Price, Source: CoinGecko

The main reason triggering the latest downfall is OKX’s decision to withdraw its support from the meme coin. The well-known cryptocurrency exchange announced that it will delist several digital assets on July 7, with BONE included in the list. 

OKX has already suspended deposits involving the token, while withdrawals will be terminated by the end of September. 

“We will continue to monitor all listed trading pairs and implement the delisting/hiding mechanism as necessary,” the company concluded.

OKX boasts over 50 million users globally and is among the behemoths in its field. When it withdraws support for a token, it often leads to negative price impacts driven by reduced liquidity, limited access, and potential reputational concerns.

BONE saw the light of day in the summer of 2021 alongside the debut of ShibaSwap – Shiba Inu’s decentralized exchange. It enables holders to vote on development proposals and influence protocol decisions, serves as a reward for liquidity providers, and functions as a gas token for Shibarium. During its early days, its price skyrocketed above $15, while currently, it trades at a mere $0.18. 

The Community’s Reaction

One person who gave their two cents on the delisting effort is the X user LUCIE, who serves as Shibarium’s marketing strategist. The team member thinks there’s much panic over two (unnamed) “manipulative” exchanges that have withdrawn their support from the token. 

LUCIE said they don’t want to be involved in the drama, putting their trust in DeFi and highlighting its advantages over centralized platforms:

“I trust DeFi. Use good exchanges only to exchange. We’re here to build and embrace DeFi – and simplify it so even beginners can onboard without needing 2FA, KYC, and a blood sample just to get started.”

Shibarium’s executive also noted that SHIB and other cryptocurrencies, like XRP, have faced similar FUD (Fear, Uncertainty, and Doubt) but have survived the backlash over the years. At the same time, LUCIE reminded about the demise of former giants like FTX and WazirX, hinting that centralized exchanges are not immune to another collapse of that type.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Continue Reading

Trending

©2021-2024 Letizo All Rights Reserved