Breaking 1inch Frontend Compromised
in Widespread Supply
Chain Attack
Decentralized exchange aggregator 1inch’s website has been breached along with
multiple other platforms that use the same frontend library, Lottie Player.
The breach originated from malicious code injected into the Lottie Player, a
widely-used animation• Кинематограф » Мультипликация library used by several dApps and non-crypto websites.
As of now, no user wallets have been reportedly compromised.
1inch Users Cautioned Against Any Interactions
Sponsored
Sponsored
According to several posts on X (formerly Twitter• Коммуникации » Интернет-коммуникации » Интернет-сообщество » Социальные сети » Х (Twitter)), 1inch and TEN Finance are
the confirmed victims of this attack so far. However, the number could be much
higher, as the exploit targeted Lottie Player versions 2.0.5 and above.
Hackers have reportedly injected malicious code into the front-end JSON files
of websites using these versions. This code now enables the compromised sites
to perform unauthorized transactions, posing a severe threat to users’ assets
and data.
Read More: 9 Crypto Wallet Security Tips To Safeguard Your Assets
Reports from Blockaid indicate that the attack was introduced through a
compromise of Lottie Player’s content server, where a malicious npm package
was used to distribute altered code. Blockaid and other security firms have
confirmed the injection of unauthorized scripts within the package.
Sponsored
Sponsored
“Legitimate sites (non crypto as well) are now serving malicious content,
including anti-debug evasion code. @LottieFiles, it looks like attackers have
managed to push malicious versions of your package, with another version being
uploaded now,” Blockaid wrote in an X (formerly Twitter• Коммуникации » Интернет-коммуникации » Интернет-сообщество » Социальные сети » Х (Twitter)) post .
At the time of writing, 1inch hasn’t released any official statement on the
breach. However, the Lottie Player team has confirmed that they were able to
identify the cause of the breach and are working on removing the affected
versions.
Users are strictly advised to avoid connecting wallets or interacting with
affected platforms until the security issues are fully resolved. Community
post on the 1inch Discord channel
Crypto Hacks Continue To Escalate
Security breaches have been the most plaguing issue of the crypto industry,
and malicious activities continue to grow every year.
Most recently, hackers reportedly stole $20 million worth of cryptocurrencies• Экономика » Финансы » Платежные средства » Платежные системы интернета » Криптовалюта
from the US government• Объект организация » Организации по алфавиту » Организации на Пр » Правительство США
• Государство » Государственное устройство США » Правительство США
• Соединённые Штаты Америки (США) » Государственное устройство США » Правительство США. The funds were also part of the $3.6 billion that the
feds seized from the Bitfinex hackers.
Sponsored
Sponsored
Blockchain• Информационные технологии » Информационно-коммуникационные технологии » Информационные технологии и телекоммуникации » Базы данных » Публичная база транзакций » Блокчейн
• Высокие технологии » Информационные технологии и телекоммуникации » Базы данных » Публичная база транзакций » Блокчейн lender Radiant Capital suffered one of the biggest hacks of this
year, losing more than $50 million. The hackers gained control of the
firm s private keys and rapidly drained these assets.
Read More: Crypto Social Media• Коммуникации » Интернет-коммуникации » Интернет-сообщество » Социальные сети Scams – How to Stay Safe
However, the investigation and prosecution of these crimes have also
intensified. FBT recently arrested the SEC X (formerly Twitter• Коммуникации » Интернет-коммуникации » Интернет-сообщество » Социальные сети » Х (Twitter)) account
hacker. The accused is a 25-year-old Alabama man named Eric Council Jr.
Earlier this year, the Council allegedly hacked the SEC’s X account and posted
false news about Bitcoin• Экономика » Финансы » Платежные средства » Платежные системы интернета » Криптовалюта » Bitcoin ETF approvals, which significantly affected the
market. Yet, the feds believe Council wasn’t the brains of this operation and
they are trying to negotiate a plea deal with him.
So far, crypto hacks have exceeded $2.1 billion in 2024, with CeFi platforms
taking the biggest hits.
Best crypto platforms in Europe | October 2024
YouHodler Explore
Wirex App Explore
Coinbase Explore
BYDFi Explore
Margex Explore
Best crypto platforms in Europe | October 2024
YouHodler Explore
Wirex App Explore
Coinbase Explore
BYDFi Explore
Margex Explore
Best crypto platforms in Europe | October 2024
YouHodler
Wirex App
Coinbase
BYDFi
Margex
Disclaimer
In adherence to the Trust Project guidelines, BeInCrypto is committed to
unbiased, transparent reporting. This news article aims to provide accurate,
timely information. However, readers are advised to verify facts independently
and consult with a professional before making any decisions based on this
content. Please note that our Terms and Conditions , Privacy Policy , and
Disclaimers have been updated.