[1/π§΅] A MASSIVE attack on the JavaScript ecosystem is currently underway. βΉοΈ
Since JavaScript is at the heart of what we use every day to browse the internet, you MUST be extra vigilant.
Let's take a look at a possible solution for the XRP ecosystem. ππ§΅
[2/13] β 1β£ First things first β
Although the entire JavaScript ecosystem is at risk, the malware appears to be targeting only a few blockchain ecosystems, based on the addresses it uses to steal funds:
βΌοΈ At risk π
[3/13] β 2β£ First things first β
The reason this is such a big deal is because of the sheer volume of weekly downloads of the maliciously patched packages.
[4/13] β 3β£ First things first β
Here's the TL;DR for you as a developer. π
[5/13] β The Malware β
One nasty thing about this malware is that checking the destination address doesn't help this time, unless you're using hardware wallets, because the address gets replaced anyway BEFORE it's signed. βΉοΈ
π You might think you're safe, but you're not.
[6/13] β 1β£ XRP Ledger / Solution β
Introducing a possible solution for the XRP ecosystem, is a draft that @krisdangerfield and @angell_denis are working on, namely:
πΈ 0086 XLS-86d: Firewall
[7/13] β 2β£ XRP Ledger / Solution β
"Firewall" would allow you to configure the following:
πΈ Time-based outgoing transactions
πΈ Value-limited safeguards
And most importantly:
βΌοΈ Creation of a whitelist mechanism
[8/13] β 3β£ XRP Ledger / Solution β
Since the malware doesn't steal PKs, the first two aspects of the "Firewall" are less important.
The whitelist on the other hand, which would've been set up to help you bypass the Firewall restrictions for everyday TXs, would protect you! π₯
[9/13] β 1β£ Firewall β
The rationale, as perfectly explained in the draft is that when enabled on an account, it will prevent an attacker from:
πΈ Instantly draining your funds
Provides you with:
πΈ Opportunity to move your XRP to an alternative account
[10/13] β 2β£ Firewall β
This essentially means that even if you would ever sign a transaction to send your funds to wrong addresses, the Firewall would protect you because the address isn't known to your configured whitelist. π«‘
[11/13] β Summary β
πΈ The JavaScript ecosystem got hijacked
πΈ Don't sign TXs using browser extensions for some time
πΈ Triple-check the destination address on the display of your hardware wallet
πΈ Check out: xrplfirewall.com
πΈ Check out: jdstaerk.substack.com/p/we-just-founβ¦
[12/13] β Krippenreiter β
I write about DLT and crypto, but primarily about XRP and the XRPL-ecosystem. π₯
If this interests you and you want to learn more, please follow me here:
@krippenreiter
[1/π§΅] You've probably heard about new yield opportunities with XRP that promise a return of around 20% APY. π§
How much truth is there to this, and what happens if you actually connect to @moremarketsxyz and deposit funds? π
[2/14] β 1β£ First things first β
π I want you to repeat after me:
"I will not deposit all my XRP into completely new DeFi protocols right after their launch, no matter the yield"
[3/14] β 2β£ First things first β
When you join any DeFi protocol, start with very small amounts (e.g., 1 XRP) to get a feel for how things work, and try to regularly withdraw everything to test whether you can realize your profits with the protocol or not. π
[1/π§΅] What's still upcoming and in the pipeline for the XRP Ledger? π§
My attempt to summarize what the brilliant @aanchalmalhotre "casually" laid out in a 25-minute talk at XRPL Apex this year. π
[2/15] β 1β£ Key-Challenges β
Privacy and compliance are at odds with each other, and balance is key.
A lot of what the TradFi world is used to and expects still doesn't exist or is purposefully different in blockchains, like transparent transactions or low confidentiality.
[3/15] β 2β£ Key-Challenges β
Institutions also expect their on-chain operations, aka transactions, to be highly customizable and controllable because of factors like internal risk management.
π They expect the XRPL to be programmable for their dedicated policies.
With all these new integrations and partnerships, I bet you are pretty much overwhelmed by all the alien-like jargon. π€¨
A little vocabulary crash course ahead π
[2/20] β 1β£ Overview β
What just happened today is nothing less than the complete onboarding of the XRPL to the vast and entire web3 blockchain ecosystem (+ Bridging protocols and available liquidity).
π All via the XRPLEVM sidechain, Axelar and @squidrouter.
[3/20] β 2β£ Overview β
What does this mean in practice? π§
πΈ New tokens on the XRPL DEX (bridged by @axelar)
πΈ Literal (and easy) any-to-any swaps (via Squid)
πΈ Liquidity from the entire web3 ecosystem (via CORAL)
πΈ Bridged XRP accessible on 80+ chains (through XRPLEVM)
USDB β Braza Group
πΈ Expected to be MiCA regulated in 2025
πΈ Fully backed by $-denominated assets
πΈ Reserves held by Braza Bank Banco de CΓ’mbio S.A.
πΈ A bank licensed and regulated by the Brazilian Central Bank
[1/π§΅] There's a new site from @Satish_nl that you should definitely check out! π§
It's @xpert_page and from what I've seen so far, it's a mix of a "mini-CV" + donation functionality via XRPL and XAHL for your online (project-) presence. π
Let's take a look at what's inside π
[2/9] β Featured Creators β
It's all brand new, so there're only a few personal pages & project pages active right now.
Later the idea is to have a complete XRPL & XAHL-based project directory that you can browse through & donate to if you want to support the guys behind it π₯
[3/9] β 1β£ First Steps β
The moment I logged in with my gmail account and paid the simple price of 20 XRP that's valid for 5 years I had to set a profile pic, a banner and create a bio.