|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Cryptocurrency News Articles
1inch Compromised After Attackers Injected Malicious Code Into Animation Library Update
Oct 31, 2024 at 04:23 pm
On Oct. 30, 1inch users encountered malicious popups that appeared unexpectedly, urging them to connect their wallets.

A recent attack on 1inch, a decentralized exchange aggregator, saw attackers injecting malicious code into an animation library update to compromise users.
The attackers specifically targeted the popular Lottie Player animation library, which is used by major companies like Apple, Spotify, and Disney for creating engaging user interfaces.
According to Blockaid, a web3 security firm, the attackers used this library to inject malicious popups into websites that appeared unexpectedly, urging users to connect their wallets. These prompts were designed to redirect users to a crypto drainer, known as “Ace drainer,” which was disguised as a standard wallet connection request.
In a post-incident report, 1inch stated that only its web dApp was affected by this attack, while all other platforms, including its mobile app and API services, remained unaffected. The team also mentioned that some users might have been affected by this incident but assured that any losses would be refunded.
To mitigate the attack, the developers urged users to “revoke ERC20 approvals from malicious addresses” and highlighted that they were “strengthening dependency management for enhanced security.”
According to cybersecurity researcher Gal Nagli, the breach occurred as a part of a large-scale supply chain attack on the Lottie Player animation library. This library is widely used for web animations by companies like Apple, Spotify, and Disney to create engaging user interfaces.
The attackers initially breached the GitHub account of a senior software engineer at LottieFiles, the publisher of the Lottie Player library. Using this access, the attackers pushed three malicious updates within a span of three hours. These updates contained code that injected a malicious popup into websites using the library.
While the attack was originally targeted towards web3 firms, Nagli warned that other websites using the affected library versions also remained vulnerable. At press time, the affected libraries had been removed from GitHub, and users were asked to upgrade to the latest version.
Cybersecurity firm Scam Sniffer reported in an Oct. 31 X post that at least one victim had lost 10 BTC, which was roughly valued at $723,436 at the time, after signing a phishing transaction, which was likely connected to the supply chain attack on Lottie Player.
Disclaimer:info@kdj.com
The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!
If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.
-
- Apple and Google Tap Stablecoin Experts, Signaling a Major Shift in Crypto Payments Strategy
- Sep 22, 2026 at 04:05 am
- Tech giants Apple and Google are actively hiring stablecoin and blockchain specialists, signaling a significant evolution in their approach to crypto payments and financial infrastructure.
-
-
- U.S. Treasury Slams Iranian Exchange BitBank with Sanctions Over Alleged IRGC Bitcoin Transfers
- Sep 21, 2026 at 04:05 am
- The U.S. Treasury Department has sanctioned Iranian crypto exchange BitBank, alleging its involvement in funneling Bitcoin to the IRGC. This action tightens the noose on Iran's digital asset infrastructure.
-
- Crypto Crossroads: Best Crypto to Buy Amidst SEC Regulation & the Rise of Pepeto
- Sep 21, 2026 at 04:05 am
- Amidst evolving SEC regulations, a new player, Pepeto, emerges as a potential 'best crypto to buy', offering innovative tools and early-bird opportunities, contrasting with established giants and fading meme coins.
-
-
- One Attacker, Multiple Tokens: Inside the Fetch.ai Breach - A New York Minute
- Sep 20, 2026 at 08:05 pm
- The Fetch.ai breach, initially thought to be a $1.5M FET token theft, has ballooned into a multi-token saga involving NTX, AGIX, and WMTX, with total attacker holdings now topping $17M. This incident highlights the critical difference between stolen and newly minted tokens, revealing deeper security implications beyond initial financial losses.
-
-
- Bitcoin, Altcoins, & Crypto-currency: A Market Surge Driven by Regulation and Innovation, Not Just Memes
- Sep 20, 2026 at 08:05 pm
- Bitcoin's unexpected leap past $80,000 ignited a broader crypto rally, fueled by shrewd regulatory moves and a distinct shift towards altcoins with genuine utility and revenue streams. This isn't your grandma's crypto market anymore.
-

































