Crypto apps see malicious popups after Ace Drainer hacks animation library
The front-end websites of several online crypto apps were compromised on Oct. 30 after attackers injected malicious code into an update of a popular and widely used animation library.
Decentralized finance apps , including 1inch and TEN Finance, showed popups asking users to connect their wallet, which was actually for the crypto drainer “Ace Drainer,” crypto security platform Blockaid said in an Oct. 30 X post .
Gal Nagli, a security lead at cybersecurity firm Wiz, explained the compromise was from a “massive supply chain attack” on the Lottie Player library — a hugely popular service that provides animations for sites and apps, boasting users like Apple, Spotify, and Disney.
Source: Blockaid
The attack is unique as it injected a malicious popup into a seemingly otherwise unaffected website. Attackers typically breach highly-followed social media accounts to trick followers into clicking phishing links on fake website s.
Jawish Hameed, the engineering vice president at LottieFiles — the firm that publishes the animations library — wrote on GitHub the affected library versions had been removed and urged users to install the latest version.
He said that attackers compromised the GitHub account of a LottieFiles’ senior software engineer and pushed three malicious updates in three hours, adding it had “removed the compromised account access.”
Related: Hacker behind fake Bitcoin ETF X post pleads not guilty
Wiz’s Nagli said users were seeing the malicious crypto wallet connection popup “on popular websites all across the internet.”
“It seems that the original attack intent was to target major crypto websites who utilize the library,” he added.
Nagli warned that websites that still use the affected library versions “are probably still vulnerable,” saying users should check if sites are using the non-malicious packages — either version 2.0.4 or the latest 2.0.8.
LottieFiles did not immediately respond to a request for comment.
Crypto-Sec: 2 auditors miss $27M Penpie flaw, Pythia’s ‘claim rewards’ bug
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Donald Trump's Son Eric Trump's Elon Musk Tactic! "After Ethereum, Bitcoin (BTC) Sharing Has Come Too!"
Eric Trump said that now is a good time to accumulate Bitcoin after Ethereum.
![](https://img.bgstatic.com/multiLang/image/social/4be3b7bc9cade9a587f0ed5bf867bc6c1738877641839.png)
JPMorgan's Huge Cryptocurrency Survey! What Do Investors Think About Bitcoin (BTC) and Altcoins?
According to JPMorgan survey results, 71% of institutional investors stated that they do not plan to trade cryptocurrencies in 2025.
Why Ethereum (ETH) Cannot Rise? JPMorgan Analysts Explained, Warned for What Happened After!
JPMorgan warns that Ethereum could continue its poor performance.
![](https://img.bgstatic.com/multiLang/image/social/ddc3470629124d1e3886b0f78f9b505f1738877637251.jpg)
SEC weighs proposal to change BlackRock's spot Bitcoin ETF to allow in-kind redemptions
The SEC asked for comments to be sent in 21 days after its filing is published in the Federal Register.Over a year ago when the SEC was considering whether to approve spot Bitcoin ETFs, firms were hashing out technical details over how the redemption process should work settling on cash, not in-kind.
![](https://img.bgstatic.com/multiLang/image/social/e7d4b3771ba9f72022470cdea688073c1738796411552.jpg)
Trending news
MoreCrypto prices
More![Bitcoin](https://img.bgstatic.com/multiLang/coinPriceLogo/bitcoin.png)
![Ethereum](https://img.bgstatic.com/multiLang/coinPriceLogo/ethereum.png)
![Tether USDt](https://img.bgstatic.com/multiLang/coinPriceLogo/0208496be4e524857e33ae425e12d4751710262904978.png)
![XRP](https://img.bgstatic.com/multiLang/coinPriceLogo/ripple.png)
![Solana](https://img.bgstatic.com/multiLang/coinPriceLogo/solana.png)
![BNB](https://img.bgstatic.com/multiLang/coinPriceLogo/binance.png)
![USDC](https://img.bgstatic.com/multiLang/coinPriceLogo/usdc.png)
![Dogecoin](https://img.bgstatic.com/multiLang/coinPriceLogo/dogecoin.png)
![Cardano](https://img.bgstatic.com/multiLang/coinPriceLogo/cardano.png)
![TRON](https://img.bgstatic.com/multiLang/coinPriceLogo/tron.png)