The XRP Ledger Foundation has disclosed a critical backdoor in its official JavaScript library, allowing attackers to steal private keys and access wallets via a refined supply chain attack.
The vulnerability was flagged as 'potentially catastrophic' by blockchain security firm Aikido.
The compromised code has been removed, and key ecosystem apps like XRPScan and First Ledger confirmed they were unaffected.