Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
Crypto apps hit by malware after animation library hack

Crypto apps hit by malware after animation library hack

GrafaGrafa2024/10/31 10:00
By:Mahathir Bayena

Several online crypto applications experienced security breaches on October 30 due to malicious code injected into a widely used animation library.

Decentralised finance platforms like 1inch and TEN Finance displayed popups urging users to connect their wallets, which were linked to the crypto-draining malware “Ace Drainer,” according to a post from security platform Blockaid.

The breach stemmed from an attack on the Lottie Player library, a popular service that provides animations for websites and apps.

Lottie Player counts high-profile companies like Apple, Spotify, and Disney among its users.

Gal Nagli, a cybersecurity expert at Wiz, described it as a “massive supply chain attack” in which hackers inserted malicious popups onto otherwise legitimate websites.

Unlike traditional phishing attacks where scammers take over social media accounts to lure users to fake websites, this attack embedded harmful code into a legitimate library update.

This approach allowed attackers to target well-known crypto platforms that used the compromised library.

Jawish Hameed, vice president of engineering at LottieFiles, confirmed the breach on GitHub.

He explained that the attackers had compromised a senior software engineer’s GitHub account and pushed three harmful updates within three hours.

Hameed reassured users that the compromised versions had been removed, and he urged them to update to the safe versions, either 2.0.4 or the latest 2.0.8.

Nagli cautioned that users might still encounter the malicious popups on websites that haven’t updated to secure versions of the Lottie Player library.

He advised users to verify if sites are using the non-compromised versions to avoid the risk.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Web3 ai Could Lead 2025’s Best Cryptos With 1,747% ROI, Outshining Toncoin & Chainlink’s Performance

Toncoin (TON) and Chainlink (LINK) show strong market positions, but Web3 ai’s AI-driven platform and sub-$0.001 price point may offer greater potential for exponential growth.Toncoin (TON): Leveraging Telegram’s Ecosystem for GrowthChainlink (LINK): Technical Indicators Point to Potential BreakoutWeb3 ai: Affordable Entry with AI-Driven Security ToolsClosing Thought

Coinomedia2025/05/24 23:40
Web3 ai Could Lead 2025’s Best Cryptos With 1,747% ROI, Outshining Toncoin & Chainlink’s Performance

Ethereum Set to Soar Past $4,000 Again

Ethereum eyes a comeback above $4,000 with a projected 55% surge amid rising market optimism.What’s Driving the Ethereum Rally?Could Ethereum Break Past Its All-Time High?

Coinomedia2025/05/24 23:40
Ethereum Set to Soar Past $4,000 Again

Lark Davis: Best Time to Make Money in Crypto

Crypto analyst Lark Davis says this is the best time to make money in crypto. Here’s why you should pay attention now.Why This Window Matters So MuchHow to Lock In for Maximum Gains

Coinomedia2025/05/24 23:40
Lark Davis: Best Time to Make Money in Crypto

Top Rated Cryptos to Buy in 2025: BlockDAG, Tron, Polygon, and Polkadot Line Up Ahead of Q3 Shift

Explore the top rated cryptos to buy in 2025, featuring BlockDAG’s limited-time 'Double Your BDAG' offer, and why Tron, Polygon, and Polkadot are gaining strong attention this year1. BlockDAG (BDAG)2. Tron (TRX)3. Polygon (MATIC)4. Polkadot (DOT)Closing View on Key 2025 Contenders

Coinomedia2025/05/24 23:40
Top Rated Cryptos to Buy in 2025: BlockDAG, Tron, Polygon, and Polkadot Line Up Ahead of Q3 Shift