Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn
1inch frontend hit by major supply chain attack

1inch frontend hit by major supply chain attack

GrafaGrafa2024/10/31 10:00
By:Mahathir Bayena

Decentralised exchange aggregator 1inch (CRYPTO:1INCH) was compromised in a widespread supply chain attack that exploited vulnerabilities in the popular Lottie Player library.

The breach involved the injection of malicious code into the front-end library, affecting multiple decentralised apps (dApps) and non-crypto websites utilising Lottie Player.

The security incident specifically impacted Lottie Player versions 2.0.5 and above, where attackers embedded unauthorised scripts into JSON files on affected sites.

This malicious code enables unauthorised transactions, posing significant risks to users’ funds and sensitive data.

Security firm Blockaid reported, “Legitimate sites (non-crypto as well) are now delivering harmful content, including anti-debug evasion code.”

Users are strongly advised to refrain from connecting wallets or engaging with compromised websites until the security flaws are fully mitigated.

While no compromised wallets have been confirmed thus far, the situation remains precarious.

According to Blockaid, the attack originated from a compromised npm package, which was disseminated via Lottie Player’s content server.

Reports suggest that the attackers managed to infiltrate the library and push altered versions, targeting crypto platforms like 1inch and TEN Finance.

However, the full extent of the breach remains unclear, with the number of affected sites likely higher.

Lottie Player’s team has identified the root cause and is actively removing the compromised versions.

They urged users to ensure that websites are running either version 2.0.4 or the latest 2.0.8 to guarantee security.

At the time of reporting, the 1inch price was $0.2583.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Trump and Wall Street: How long will the love affair last?

Share link:In this post: Wall Street loved Trump’s win at first—stocks jumped, Bitcoin soared, and borrowing costs hit rock bottom, but some sectors started cracking fast. Tax cuts and deregulation made financial and energy stocks shoot up, but tariffs and plans to deport workers freaked out economists and markets. Tariffs mean higher prices for Americans, and even Walmart’s warning it’ll have to raise prices if Trump pushes through with his trade war.

Cryptopolitan2024/11/24 03:44

How AI could transform Germany’s economic future

Share link:In this post: Germany must innovate to stay competitive with rapid AI advancements. Germany prioritizes safety, slowing progress compared to risk-tolerant nations. Bold investments and ethical AI are key to Germany’s leadership.

Cryptopolitan2024/11/24 03:44

How Black Ops 6 plans to stop ranked play cheating

Share link:In this post: Treyarch has addressed the cheating issues in Call of Duty: Ranked Play mode in Black Ops 6. The mode was released last week and already getting complaints of cheating. Treyarch may be increasing its workforce to deal with increasing complaints.

Cryptopolitan2024/11/24 03:44

The clash of Bitcoin and benchmark stock indexes

Share link:In this post: The S&P 500 is up 25% this year, with financial and cyclical stocks leading, boosted by optimism around a Trump administration and steady economic growth. Bitcoin has surged 40% this month, nearing $100,000, driven by aggressive trading, retail investor enthusiasm, and headlines hinting at government support. MicroStrategy’s stock hit a $100 billion market cap, tripling its Bitcoin holdings’ value, but its wild 32% drop from intraday highs shows cracks in the frenzy.

Cryptopolitan2024/11/24 03:44