Krippenreiter Profile picture
Sep 8 β€’ 14 tweets β€’ 5 min read β€’ Read on X
[1/🧡] A MASSIVE attack on the JavaScript ecosystem is currently underway. ☹️

Since JavaScript is at the heart of what we use every day to browse the internet, you MUST be extra vigilant.

Let's take a look at a possible solution for the XRP ecosystem. πŸ‘‡πŸ§΅ Source: https://xrplfirewall.com
[2/13] β€” 1⃣ First things first β€”

Although the entire JavaScript ecosystem is at risk, the malware appears to be targeting only a few blockchain ecosystems, based on the addresses it uses to steal funds:

‼️ At risk πŸ‘‡ Source: https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the
[3/13] β€” 2⃣ First things first β€”

The reason this is such a big deal is because of the sheer volume of weekly downloads of the maliciously patched packages. Source: https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the
[4/13] β€” 3⃣ First things first β€”

Here's the TL;DR for you as a developer. πŸ‘‡ Source: https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the
[5/13] β€” The Malware β€”

One nasty thing about this malware is that checking the destination address doesn't help this time, unless you're using hardware wallets, because the address gets replaced anyway BEFORE it's signed. ☹️

πŸ‘‰ You might think you're safe, but you're not. Source: https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the
[6/13] β€” 1⃣ XRP Ledger / Solution β€”

Introducing a possible solution for the XRP ecosystem, is a draft that @krisdangerfield and @angell_denis are working on, namely:

πŸ”Έ 0086 XLS-86d: Firewall Source: https://xrplfirewall.com
[7/13] β€” 2⃣ XRP Ledger / Solution β€”

"Firewall" would allow you to configure the following:
πŸ”Έ Time-based outgoing transactions
πŸ”Έ Value-limited safeguards

And most importantly:
‼️ Creation of a whitelist mechanism Source: https://xrplfirewall.com
[8/13] β€” 3⃣ XRP Ledger / Solution β€”

Since the malware doesn't steal PKs, the first two aspects of the "Firewall" are less important.

The whitelist on the other hand, which would've been set up to help you bypass the Firewall restrictions for everyday TXs, would protect you! πŸ”₯ Source: https://xrplfirewall.com
[9/13] β€” 1⃣ Firewall β€”

The rationale, as perfectly explained in the draft is that when enabled on an account, it will prevent an attacker from:
πŸ”Έ Instantly draining your funds

Provides you with:
πŸ”Έ Opportunity to move your XRP to an alternative account Source: https://xrplfirewall.com
[10/13] β€” 2⃣ Firewall β€”

This essentially means that even if you would ever sign a transaction to send your funds to wrong addresses, the Firewall would protect you because the address isn't known to your configured whitelist. 🫑 Source: https://xrplfirewall.com
[11/13] β€” Summary β€”

πŸ”Έ The JavaScript ecosystem got hijacked
πŸ”Έ Don't sign TXs using browser extensions for some time
πŸ”Έ Triple-check the destination address on the display of your hardware wallet
πŸ”Έ Check out: xrplfirewall.com
πŸ”Έ Check out: jdstaerk.substack.com/p/we-just-foun… Source: @Krippenreiter
[12/13] β€” Krippenreiter β€”

I write about DLT and crypto, but primarily about XRP and the XRPL-ecosystem. πŸ”₯

If this interests you and you want to learn more, please follow me here:
@krippenreiter

Feel free to contribute by sharing here πŸ‘‡
[13/13] β€” Support & Donate β€” Source: @Krippenreiter
@threadreaderapp unroll

β€’ β€’ β€’

Missing some Tweet in this thread? You can try to force a refresh
γ€€

Keep Current with Krippenreiter

Krippenreiter Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @krippenreiter

Jul 26
[1/🧡] You've probably heard about new yield opportunities with XRP that promise a return of around 20% APY. 🧐

How much truth is there to this, and what happens if you actually connect to @moremarketsxyz and deposit funds? πŸ‘‡
[2/14] β€” 1⃣ First things first β€”

πŸ‘‰ I want you to repeat after me:

"I will not deposit all my XRP into completely new DeFi protocols right after their launch, no matter the yield" Source: @krippenreiter
[3/14] β€” 2⃣ First things first β€”

When you join any DeFi protocol, start with very small amounts (e.g., 1 XRP) to get a feel for how things work, and try to regularly withdraw everything to test whether you can realize your profits with the protocol or not. πŸ‘ Source: https://app.moremarkets.xyz
Read 15 tweets
Jul 7
[1/🧡] What's still upcoming and in the pipeline for the XRP Ledger? 🧐

My attempt to summarize what the brilliant @aanchalmalhotre "casually" laid out in a 25-minute talk at XRPL Apex this year. πŸ‘‡ Source: https://www.youtube.com/watch?v=UzbHAbBtLXQ
[2/15] β€” 1⃣ Key-Challenges β€”

Privacy and compliance are at odds with each other, and balance is key.

A lot of what the TradFi world is used to and expects still doesn't exist or is purposefully different in blockchains, like transparent transactions or low confidentiality. Source: https://www.youtube.com/watch?v=UzbHAbBtLXQ
[3/15] β€” 2⃣ Key-Challenges β€”

Institutions also expect their on-chain operations, aka transactions, to be highly customizable and controllable because of factors like internal risk management.

πŸ‘‰ They expect the XRPL to be programmable for their dedicated policies. Source: https://www.youtube.com/watch?v=UzbHAbBtLXQ
Read 16 tweets
Jun 30
[1/🧡] XRP Ledger βœ– Axelar βœ– XRPL EVM Sidechain βœ– Squid ‼️

With all these new integrations and partnerships, I bet you are pretty much overwhelmed by all the alien-like jargon. 🀨

A little vocabulary crash course ahead πŸ‘‡ Source: https://axelarscan.io
[2/20] β€” 1⃣ Overview β€”

What just happened today is nothing less than the complete onboarding of the XRPL to the vast and entire web3 blockchain ecosystem (+ Bridging protocols and available liquidity).

πŸ‘‰ All via the XRPLEVM sidechain, Axelar and @squidrouter. Source: https://axelarscan.io
[3/20] β€” 2⃣ Overview β€”

What does this mean in practice? 🧐
πŸ”Έ New tokens on the XRPL DEX (bridged by @axelar)
πŸ”Έ Literal (and easy) any-to-any swaps (via Squid)
πŸ”Έ Liquidity from the entire web3 ecosystem (via CORAL)
πŸ”Έ Bridged XRP accessible on 80+ chains (through XRPLEVM) Source: @squidrouter
Read 21 tweets
May 22
[1/🧡] Bonjour πŸ‡ͺπŸ‡Ί and Bom dia πŸ‡§πŸ‡·!

Two new stablecoins just launched on the XRP Ledger:
πŸ”Έ EURØP (EUR-backed by Schuman Financial)
πŸ”Έ USDB (USD-backed by Braza Group)

A quick peek behind the curtain. πŸ‘‡ Source: @Krippenreiter
[2/14] β€” πŸ‡ͺπŸ‡Ί Overview β€”

EURØP βœ– Schuman Financial
πŸ”Έ MiCA-compliant regulated e-money token
πŸ”Έ Fully backed by €-denominated assets
πŸ”Έ Held in segregated accounts, separate from their corporate accounts
πŸ”Έ Supervised by AutoritΓ© de ContrΓ΄le Prudentiel et de RΓ©solution (ACPR) Source: https://schuman.io/europ/
[3/14] β€” πŸ‡§πŸ‡· Overview β€”

USDB βœ– Braza Group
πŸ”Έ Expected to be MiCA regulated in 2025
πŸ”Έ Fully backed by $-denominated assets
πŸ”Έ Reserves held by Braza Bank Banco de CΓ’mbio S.A.
πŸ”Έ A bank licensed and regulated by the Brazilian Central Bank Source: https://brazabank.com.br/conteudo/usdb-stablecoin-braza/
Read 15 tweets
May 10
[1/🧡] There are alot of usecases for on-chain verifiable credentials. 🧐

Most of them are far more powerful than you can imagine.

(long read ahead of you) πŸ‘‡ Source: https://ec.europa.eu/digital-building-blocks/sites/display/EBSI/EBSI+Verifiable+Credentials
[2/16] β€” Digital ID & Authentication Council of Canada (DIACC) β€” Source: https://diacc.ca/wp-content/uploads/2023/05/Perspectives-on-the-Adoption-of-Verifiable-Credentials-1.pdf
[3/16] β€” European Blockchain Services Infrastructure (EBSI) β€” Source: https://ec.europa.eu/digital-building-blocks/sites/display/EBSI/Spain+plans+to+use+W3C+Verifiable+Credentials+to+protect+minors+online
Read 17 tweets
May 3
[1/🧡] There's a new site from @Satish_nl that you should definitely check out! 🧐

It's @xpert_page and from what I've seen so far, it's a mix of a "mini-CV" + donation functionality via XRPL and XAHL for your online (project-) presence. πŸ˜€

Let's take a look at what's inside πŸ‘‡ Source: https://x.com/xpert_page/header_photo
[2/9] β€” Featured Creators β€”

It's all brand new, so there're only a few personal pages & project pages active right now.

Later the idea is to have a complete XRPL & XAHL-based project directory that you can browse through & donate to if you want to support the guys behind it πŸ”₯ Source: https://xpert.page/#features
[3/9] β€” 1⃣ First Steps β€”

The moment I logged in with my gmail account and paid the simple price of 20 XRP that's valid for 5 years I had to set a profile pic, a banner and create a bio. Source: https://xpert.page/pro/profile
Read 10 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(