The XRPL Foundation is patching a “critical” vulnerability that almost leaked to the mainnet

Featured in:
abcd

The XRP Ledger Foundation has confirmed that it has patched a critical security vulnerability found in Ripple’s yet-to-be-enabled XRP Ledger patch, preventing a potentially solemn exploit.

On February 19, a security engineer at cybersecurity firm Cantina, Pranamya Keshkamat, and the Cantina AI security bot identified a “critical logic error” in the signature validation logic of the Ripple blockchain, XRP Ledger, reported XRP Ledger Foundation on Thursday.

sadasda

A vulnerability in the signature verification code package patch would allow an attacker to perform transactions from victims’ accounts, including draining funds, without requiring the victim’s private keys.

“The fix was in the voting phase and was not activated on the mainnet; no funds were at risk,” XPLF stated.

Source: XRP Ledger Foundation

Exploitation could destabilize the ecosystem

In addition to the potential for theft of funds and modification of the ledger state, the vulnerability could have “destabilized the ecosystem,” XPLF said.

“A successful large-scale exploit could result in a significant loss of trust in XRPL, which could potentially cause significant disruption to the broader ecosystem.”

Related: Cybersecurity stocks fall after Anthropic launches Claude Code Security

Cantina and Spearbit CEO Hari Mulackal he said“Our autonomous bug hunter Apex found this critical bug.”

“If exploited, it would be the world’s largest security hack in terms of dollar value, with an immediate risk of almost $80 billion,” he added, likely referring to XRP (XRP) market capitalization.

The emergence of AI cybersecurity scanners

An autonomous AI security tool developed by Cantina AI identified the vulnerability through “static analysis of the collapsed codebase” and provided a disclosure report, allowing Ripple’s engineering teams to inspect it and begin patching the code.

Validators were asked to vote against the patch, and an emergency release (version 3.1.1) was published on February 23 to block activation of the patch, XPLF said.

Artificial intelligence is increasingly being deployed for cybersecurity purposes to detect errors in code that can be missed by human eyes.

Anthropic’s February 20 release of Claude Code Security, an artificial intelligence-based cyber vulnerability scanner that it claims “can reason like a skilled security researcher,” caused shares of public IT security companies to tumble on February 20.

Warehouse: Artificial Intelligence Won’t Make You Rich, But Crypto Gaming Can, Axie Founder Steps Down: Web3 Gamer

Cointelegraph is committed to independent and limpid journalism. This news article has been produced in accordance with Cointelegraph’s Editorial Policy and is intended to provide right and up-to-date information. Readers are encouraged to verify the information themselves. Read our Editorial Policy https://cointelegraph.com/editorial-policy
abcd
sadasda

Find us on

Latest articles

Related articles

See more articles

SpaceX’s IPO is nearing 4x oversubscription, squeezing cryptocurrencies and...

Elon Musk's SpaceX initial public offering has reportedly seen oversubscription rates nearly quadruple the planned offering size,...

Bitcoin Comes Back to Production Costs: Analyst Says Best...

The founder of Capriole Investments emphasized that Bitcoin is at the threshold of a zone that has...

Solana Institute CEO says the CLARITY Act must protect...

Solana Institute CEO Kristin Smith is urging the US Senate to pass the CLARITY Crypto Market Structure...

XRP is oversold on every time frame and this...

XRP is currently oversold on all major time frames, signaling weakening momentum as its price continues to...

ETH is in danger of falling to 1,000. dollars...

In the Ether (ETH) futures market, open interest (OI) on Gate.io has dropped by 45% to levels...

XRP is testing major macro support as bulls and...

My name is Godspower Owie, I was born and raised in Edo State, Nigeria. I grew up...