XRP Security Breach: Private Keys Compromised by Software Supply Chain Attack

A major security breach affecting the XRP Ledger has been revealed. A vulnerability in a JavaScript library named xrpl.js, responsible for handling transactions on the network, was exploited in a software supply chain attack. The exploit allowed malicious code to access user private keys and potentially steal funds. 🛡️ This critical issue was discovered by Aikido Security and confirmed by Ripple CTO David Schwartz. It specifically affects versions of the Node Package Manager (NPM) library up to version 4.2.4 and 2.14.2. However, newer versions 4.2.5 and 2.14.3 address the vulnerability.