• Home
  • About Us
  • Privacy Policy
  • Terms and Conditions
  • Team
  • Contact
Saturday, May 31, 2025
FinCurrency
No Result
View All Result
  • Home
  • News
  • Finance
  • Economy
  • Crypto
  • Home
  • News
  • Finance
  • Economy
  • Crypto
No Result
View All Result
FinCurrency
No Result
View All Result

Lottie Player Compromised, Users Lose 10 BTC!

Andras Crow-Hreidar by Andras Crow-Hreidar
October 31, 2024
in Crypto, News
Reading Time: 2 mins read
A A
0
Lottie Player Compromised, Users Lose 10 BTC!
0
SHARES
0
VIEWS
FacebookTweetPinShareShare

In a significant and coordinated strike against the web3 ecosystem, vigilant on-chain investigators have uncovered a vast supply chain attack targeting Lottie Player. Earlier today, the LottieFiles team reported that attackers had successfully integrated bugs into multiple versions of the Lottie Player, specifically versions 2.05, 2.06, and 2.0.7. These compromised versions were subsequently uploaded and made available on GitHub’s npm platform.

Details of the Compromise

Alarmingly, the unauthorized versions contained malicious code that prompted users to connect their cryptocurrency wallets. Numerous users, who accessed the library via third-party Content Delivery Networks (CDNs) without specifying a particular version, were automatically served the compromised version as the latest release. As the incident unfolds, the LottieFiles team is actively investigating, suspecting that a developer with the necessary permissions may have facilitated the breach.

blockdag 70m

Response and Mitigation

To address the issue, the LottieFiles team has released a secure version, labeled 2.0.8, which mirrors the original Lottie Player version 2.0.4. In a crucial move to prevent further damage, the compromised package versions have been removed from the npm platform. Additionally, the team has revoked all access and related service accounts of the implicated developer, ensuring enhanced security measures going forward.

Impact of the Lottie Player Supply Chain Attack

The repercussions of the Lottie Player supply chain attack have been significant. As reported by the on-chain analysis platform Scam Sniffer, several leading decentralized applications (Dapps), including 1inch (1INCH) and Movement network, have been compromised. The attackers aimed to siphon off users’ funds, leading the 1inch protocol to commit to reimbursing all affected users via its network.

Steps for Affected Users

The 1inch team has issued a crucial advisory for all impacted users, recommending the revocation of ERC20 smart contract approvals from malicious addresses using the revoke.cash platform. This proactive measure is essential to prevent any further financial losses. According to on-chain data analysis, the Lottie Player supply chain attack has already led to substantial losses, with one web3 user losing 10 Bitcoins, valued at over $720,000.

Conclusion

The Lottie Player supply chain attack serves as a stark reminder of the vulnerabilities that can exist within the web3 space. It underscores the importance of vigilance and the need for robust security measures to protect decentralized applications and their users. As the LottieFiles team continues its investigation, the broader web3 community must remain alert and take proactive steps to secure their digital assets and platforms against such threats.

“`

This enriched article includes structured headings and expanded content for SEO purposes, ensuring a comprehensive overview of the incident while maintaining originality.

Tags: crypto scamHack
Previous Post

Tether’s $1 Billion USDT Mint On Tron: What’s Fueling The Demand Surge?

Next Post

Bitcoin Consolidates Near ATH – Volume Suggests A Big Move Ahead

Andras Crow-Hreidar

Andras Crow-Hreidar

Hi there, my name is András and I'm a business and finance journalist living in Norway. My passion lies in uncovering the latest stories in the world of finance and delivering them to my readers in a way that's clear and engaging. I cover a wide range of topics in the finance world, including cryptocurrencies, which I believe have the potential to transform the way we interact with money and financial systems.As a journalist, I'm committed to providing my readers with accurate and reliable reporting. I believe that access to high-quality information is essential for making informed decisions, whether it's about personal finances or investments. When I'm not writing about finance, I enjoy a variety of hobbies and interests.

Next Post
Bitcoin Consolidates Near ATH – Volume Suggests A Big Move Ahead

Bitcoin Consolidates Near ATH – Volume Suggests A Big Move Ahead

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result

Popular News

  • How BlockDAG’s Community-First Strategy Raised $68.3M in Presale; Cardano To Roll out New Update & Solana Price Prediction Bullish

    How BlockDAG’s Community-First Strategy Raised $68.3M in Presale; Cardano To Roll out New Update & Solana Price Prediction Bullish

    0 shares
    Share 0 Tweet 0
  • Top 10 Altcoins Under $1 to Invest in 2025

    0 shares
    Share 0 Tweet 0
  • Alex Mashinsky Net Worth: From Tech Pioneer to Legal Battle

    0 shares
    Share 0 Tweet 0
  • Vanguard Routing Number: How to Find and Use It

    0 shares
    Share 0 Tweet 0
  • How to Earn Passive Income? Embrace the Future of Passive Income and Earn 20% Instant USDT with Caged Beasts Coin

    0 shares
    Share 0 Tweet 0

Recent News

$12k Void Opens Up Possibility Of Crash Toward $75,000

$12k Void Opens Up Possibility Of Crash Toward $75,000

January 11, 2025
Phishing, Fake Mining Scams, and $474K Loss in One Week

Phishing, Fake Mining Scams, and $474K Loss in One Week

January 11, 2025
3 kleine crypto’s met potentie

3 kleine crypto’s met potentie

January 11, 2025
Unbelievable 1000x Return in Just 12 Hours!

Crypto Whale Bags $4.9M in Profit with Solana’s AI Meme Coin

January 11, 2025
FinCurrency Logo White Mode Retina Mobile

FinCurrency is a user-friendly platform that stands out as a unique source where our strong team of experienced and academically qualified writers, who are experts in their fields, analyze current issues and global affairs related to the finance and crypto world in an enjoyable and non-technical approach.

$12k Void Opens Up Possibility Of Crash Toward $75,000

$12k Void Opens Up Possibility Of Crash Toward $75,000

January 11, 2025
Phishing, Fake Mining Scams, and $474K Loss in One Week

Phishing, Fake Mining Scams, and $474K Loss in One Week

January 11, 2025
3 kleine crypto’s met potentie

3 kleine crypto’s met potentie

January 11, 2025
Unbelievable 1000x Return in Just 12 Hours!

Crypto Whale Bags $4.9M in Profit with Solana’s AI Meme Coin

January 11, 2025

WARNING:

The content on this site should not be considered investment advice and we are not authorised to provide investment advice. Nothing on this website is an endorsement or recommendation of a particular trading strategy or investment decision. The information on this website is general in nature so you must consider the information in light of your objectives, financial situation and needs.
Investing is speculative. When investing your capital is at risk. This site is not intended for use in jurisdictions in which the trading or investments described are prohibited and should only be used by such persons and in such ways as are legally permitted. Your investment may not qualify for investor protection in your country or state of residence, so please conduct your own due diligence or obtain advice where necessary. This website is free for you to use but we may receive a commission from the companies we feature on this site.

  • Home
  • About Us
  • Privacy Policy
  • Terms and Conditions
  • Team
  • Contact

© 2024 FinCurrency - Global News

No Result
View All Result
  • Home
  • News
  • Economy
  • Finance
  • Crypto
  • Technology
  • Terms and Conditions
  • Contact

© 2024 FinCurrency - Global News

Banner 1
Banner 2
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Terms and Conditions.