Close Menu
  • Home
  • AI
    • Web3
    • Gaming
  • Bitcoin
    • CBDCs
    • DeFi
    • Ethereum
    • Layer2
    • Macro
    • Memecoins
    • NFT
    • NFTs
    • Stablecoins
  • Banking
    • Bankruptcy
    • Censorship
    • Crime
  • Policies
    • Regulation
    • Legal
    • Exchanges
    • Privacy
  • All Posts
What's Hot

JP Morgan Predicts Bitcoin Will Surpass Gold as the Crypto Derivatives Market Grows

May. 19, 2025

Economists Support Ethereum Founder Vitalik Buterin as a Candidate for the Nobel Prize

May. 19, 2025

Grok Under Scrutiny: AI Accused of Incorporating ‘White Genocide’ Allegations into Irrelevant Responses

May. 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Coin Forge HubCoin Forge Hub
Subscribe
  • Home
  • AI
    • Web3
    • Gaming
  • Bitcoin
    • CBDCs
    • DeFi
    • Ethereum
    • Layer2
    • Macro
    • Memecoins
    • NFT
    • NFTs
    • Stablecoins
  • Banking
    • Bankruptcy
    • Censorship
    • Crime
  • Policies
    • Regulation
    • Legal
    • Exchanges
    • Privacy
  • All Posts
Coin Forge HubCoin Forge Hub
Home » Typography Elements » Lottie Player Animation Tool Targeted in Supply Chain Attack Resulting in 723K Bitcoin Theft
Bitcoin

Lottie Player Animation Tool Targeted in Supply Chain Attack Resulting in 723K Bitcoin Theft

By adminNov. 5, 2024No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Lottie Player Animation Tool Targeted in Supply Chain Attack Resulting in 723K Bitcoin Theft
Lottie Player Animation Tool Targeted in Supply Chain Attack Resulting in 723K Bitcoin Theft
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

A major security breach has impacted multiple decentralized applications (dApps), with the attack stemming from malicious code injected into Lottie Player, a widely-used JavaScript animation library.

The attack exploited recent updates to Lottie Player’s npm package, specifically in versions 2.0.5 through 2.0.7, where hackers embedded malicious code within JSON files that display animations on websites.

At least one individual has lost 10 BTC (US$723,000) after unknowingly signing a phishing transaction linked to the breach, according to Scam Sniffer, a platform designed to protect users from online fraud.

Blockaid, a cybersecurity platform monitoring the incident, confirmed Wednesday the attackers deployed a fake wallet connection prompt, leading users to the drainer malware “Ace Drainer,” which mimics legitimate connections to deceive users.

According to Blockaid, the hackers added harmful code into Lottie Player’s files, turning these animations into entry points for potential scams. Essentially, when users visited sites with this compromised library, they were shown fake pop-ups asking them to connect their digital wallets.

However, these prompts were controlled by hackers and could grant them unauthorized access to users’ funds.

In response to the attack, LottieFiles’ vice president of engineering, Jawish Hameed, confirmed Wednesday that affected versions were removed from npm, and a safe version (2.0.8) was released.

LottieFiles pointed Decrypt to its public statement regarding the breakdown of events when asked for comment.

Hameed noted the breach involved the GitHub account of a senior engineer, through which attackers pushed three compromised updates in just three hours on Tuesday.

LottieFiles has since revoked all access from the affected developer account and taken further steps to prevent future incidents.

This type of “supply chain attack”—where hackers infiltrate widely-used software that many websites rely on—can have widespread consequences. In this case, the compromised Lottie Player versions were automatically pulled into many sites, making it easier for hackers to reach users.

Decentralized aggregator platform 1inch, one of the main targets of the attack, reassured users on social media that only its web dApp was affected and that the wallet app and core protocols remain secure.

Security compromises in widely used libraries and tools have become a critical issue as hackers exploit vulnerabilities that allow them access to unsuspecting users’ assets.

Earlier this month, a PEPE token holder lost $1.39 million after unknowingly signing a malicious Permit2 transaction.

Edited by Sebastian Sinclair

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleBitcoin ETF Momentum Slows After SixDay Streak
Next Article IMX an Ethereum Gaming Token Drops Following Immutables Disclosure of SEC Warning

Related Posts

CryptoPunks NFT Sold for $6 Million in Ethereum—Resulting in a $10 Million Loss

May. 19, 2025

ConstitutionDAO for the Apocalypse: Solana NFT Initiative Seeks to Acquire Nuclear Bunker

May. 19, 2025

Malaysia’s Largest Energy Company Reports a 300% Increase in Power Theft Associated with Cryptocurrency

May. 14, 2025
Leave A Reply Cancel Reply

Latest Posts

JP Morgan Predicts Bitcoin Will Surpass Gold as the Crypto Derivatives Market Grows

May. 19, 2025

Economists Support Ethereum Founder Vitalik Buterin as a Candidate for the Nobel Prize

May. 19, 2025

Grok Under Scrutiny: AI Accused of Incorporating ‘White Genocide’ Allegations into Irrelevant Responses

May. 19, 2025

This Week in Cryptocurrency Games: Square Enix and Sony, Adidas on Sui, Coinbase Sponsors ‘League’ Esports

May. 19, 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss

Every Bitcoin Holder Will Eventually Become an Internationalist

By adminAug. 15, 1971

Over the weekend, BTC surged back towards the 30-day moving average, hovering around 69k. The opport…

Brave Souls Take the Lead in the Bitcoin Time Tunnel with OKX Web3

May. 22, 2010

The Ultimate Power Play: Masters and Minions in the World of Positions

Jul. 6, 2010
About Us
About Us

Explore the latest developments in cryptocurrency and blockchain technology with comprehensive and timely coverage, in-depth analysis, and expert insights from Coin Forge Hub.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

JP Morgan Predicts Bitcoin Will Surpass Gold as the Crypto Derivatives Market Grows

May. 19, 2025

Economists Support Ethereum Founder Vitalik Buterin as a Candidate for the Nobel Prize

May. 19, 2025

Grok Under Scrutiny: AI Accused of Incorporating ‘White Genocide’ Allegations into Irrelevant Responses

May. 19, 2025
Most Popular

Every Bitcoin Holder Will Eventually Become an Internationalist

Aug. 15, 1971

Brave Souls Take the Lead in the Bitcoin Time Tunnel with OKX Web3

May. 22, 2010

The Ultimate Power Play: Masters and Minions in the World of Positions

Jul. 6, 2010
© 2025 Coin Forge Hub All rights reserved.
  • Home
  • AI
    • Web3
    • Gaming
  • Bitcoin
    • CBDCs
    • DeFi
    • Ethereum
    • Layer2
    • Macro
    • Memecoins
    • NFT
    • NFTs
    • Stablecoins
  • Banking
    • Bankruptcy
    • Censorship
    • Crime
  • Policies
    • Regulation
    • Legal
    • Exchanges
    • Privacy
  • All Posts

Type above and press Enter to search. Press Esc to cancel.