bitcoin
bitcoin

$89614.14 USD 

0.55%

ethereum
ethereum

$3046.91 USD 

-2.78%

tether
tether

$1.00 USD 

-0.03%

solana
solana

$211.86 USD 

-1.78%

bnb
bnb

$613.27 USD 

-3.61%

dogecoin
dogecoin

$0.361476 USD 

-8.88%

xrp
xrp

$0.871314 USD 

13.64%

usd-coin
usd-coin

$0.999980 USD 

0.00%

cardano
cardano

$0.676686 USD 

21.32%

tron
tron

$0.187394 USD 

4.70%

shiba-inu
shiba-inu

$0.000024 USD 

-4.82%

toncoin
toncoin

$5.38 USD 

1.12%

avalanche
avalanche

$32.42 USD 

-0.08%

sui
sui

$3.32 USD 

-1.68%

pepe
pepe

$0.000022 USD 

-4.69%

Cryptocurrency News Articles

1inch Compromised After Attackers Injected Malicious Code Into Animation Library Update

Oct 31, 2024 at 04:23 pm

On Oct. 30, 1inch users encountered malicious popups that appeared unexpectedly, urging them to connect their wallets.

1inch Compromised After Attackers Injected Malicious Code Into Animation Library Update

A recent attack on 1inch, a decentralized exchange aggregator, saw attackers injecting malicious code into an animation library update to compromise users.

The attackers specifically targeted the popular Lottie Player animation library, which is used by major companies like Apple, Spotify, and Disney for creating engaging user interfaces.

According to Blockaid, a web3 security firm, the attackers used this library to inject malicious popups into websites that appeared unexpectedly, urging users to connect their wallets. These prompts were designed to redirect users to a crypto drainer, known as “Ace drainer,” which was disguised as a standard wallet connection request.

In a post-incident report, 1inch stated that only its web dApp was affected by this attack, while all other platforms, including its mobile app and API services, remained unaffected. The team also mentioned that some users might have been affected by this incident but assured that any losses would be refunded.

To mitigate the attack, the developers urged users to “revoke ERC20 approvals from malicious addresses” and highlighted that they were “strengthening dependency management for enhanced security.”

According to cybersecurity researcher Gal Nagli, the breach occurred as a part of a large-scale supply chain attack on the Lottie Player animation library. This library is widely used for web animations by companies like Apple, Spotify, and Disney to create engaging user interfaces.

The attackers initially breached the GitHub account of a senior software engineer at LottieFiles, the publisher of the Lottie Player library. Using this access, the attackers pushed three malicious updates within a span of three hours. These updates contained code that injected a malicious popup into websites using the library.

While the attack was originally targeted towards web3 firms, Nagli warned that other websites using the affected library versions also remained vulnerable. At press time, the affected libraries had been removed from GitHub, and users were asked to upgrade to the latest version.

Cybersecurity firm Scam Sniffer reported in an Oct. 31 X post that at least one victim had lost 10 BTC, which was roughly valued at $723,436 at the time, after signing a phishing transaction, which was likely connected to the supply chain attack on Lottie Player.

News source:crypto.news

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Nov 16, 2024