Sunday, November 16, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Crypto Hackers Strike Again: Lottie Player Compromised, Users Lose 10 BTC!

by DigestWire member
October 31, 2024
in Blockchain, Crypto Market, Cryptocurrency
0
Crypto Hackers Strike Again: Lottie Player Compromised, Users Lose 10 BTC!
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Radiant Capital Hack How a Multisig Flaw Led to a $50M Loss

The post Crypto Hackers Strike Again: Lottie Player Compromised, Users Lose 10 BTC! appeared first on Coinpedia Fintech News

In a major coordinated attack on the web3 space, on-chain sleuths discovered a massive supply chain attack on Lottie Player earlier today. According to the LottieFiles team, the attackers managed to plug in bugs into several Lottie Player versions – including 2.05, 2.06, and 2.0.7. Notably, the said versions were uploaded and published on GitHub’s npm platform.

“The unauthorized versions contained code that prompted for connecting to user’s crypto wallets. A large number of users using the library via third-party CDNs without a pinned version were automatically served the compromised version as the latest release,” the LottieFiles team noted. 

Immediate Mitigating Action

The LottieFiles team is currently investigating the incident as it is believed that a developer with the required privileges facilitated the attack. The LottieFiles team noted that it has published a new safe version dubbed 2.0.8, which is a copy of the original Lottie Player version 2.0.4.

TLDR: Massive Supply Chain attack had been happening on the highly popular JS Library lottie-player since ~2 hours ago that populates attackers Web3 wallet connection pop-up on legitimate websites.

I'll write here what we know, what can be done and how to detect it in the wild.… pic.twitter.com/aX4DIj7Olp

— Nagli (@galnagli) October 31, 2024

Most importantly, the LottieFiles team has unpublished the compromised package versions from the npm platform to mitigate further damage.

Additionally, the LottieFiles team removed all access and associated service accounts of the impacted developer.

Impact of the Lottie Player Supply Chain Attack

⚠ Lottie Player faced a supply chain attack earlier today, impacting projects like 1inch and Movement.

Our system automatically blocked the affected domains to keep you safe! 🚫🔒 pic.twitter.com/liQPFY2vY2

— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) October 31, 2024

According to the on-chain analysis platform Scam Sniffer, the Lottier Player supply chain attack compromised major decentralized applications (Dapps) led by 1inch (1INCH), and Movement network. With the attacker having the motive of draining users’ funds, the 1inch protocol has pledged to refund all the affected users through its network. 

Meanwhile, the 1-inch team has advised all affected users to revoke the ERC20 smart contract approvals from malicious addresses using revoke.cash to prevent further harm. According to on-chain data analysis, a web3 user lost 10 Bitcoins, worth over 720k, earlier today due to the Lottie Player supply chain attack.

Read Entire Article
Tags: BlockchainCoin SurgesCoinPedia
Share30Tweet19
Next Post
Ripple vs SEC Update: Could Political Endorsements Decide XRP’s Fate?

Ripple vs SEC Update: Could Political Endorsements Decide XRP’s Fate?

Dogecoin Price Prediction: DOGE Surges 22% In A Week As This Innovative Staking Meme Coin Storms Toward $3 Million

Dogecoin Price Prediction: DOGE Surges 22% In A Week As This Innovative Staking Meme Coin Storms Toward $3 Million

Tether’s $1 Billion USDT Mint On Tron: What’s Fueling The Demand Surge?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

From roadways to classrooms, this New Mexico program is bringing women’s history out of the shadows

UMFK seeks public input to mark its 150th anniversary

The conservative effort to take over Maine’s school boards stalled this November

Maine man cultivates hundreds of small, flat fruit trees

Thousands march in Gen Z protests against crime and corruption in Mexico

Bitcoin Price Prediction: Short-Term Bounce On Cards, But With a Twist

Trending

President Trump Downplays Jeffrey Epstein Email Scandal on ‘SNL,’ Offers to Sell Copies of Infamous ‘Blowing Bubba’ Message
Entertainment

President Trump Downplays Jeffrey Epstein Email Scandal on ‘SNL,’ Offers to Sell Copies of Infamous ‘Blowing Bubba’ Message

by DigestWire member
November 16, 2025
0

Jeffrey Epstein’s just-released emails were the topic of conversation on the cold open of the Nov. 15...

Melissa McCarthy to Host ‘SNL’ in December With Musical Guest Dijon

Melissa McCarthy to Host ‘SNL’ in December With Musical Guest Dijon

November 16, 2025
South Carolina looks at most restrictive abortion bill in the US as opponents keep pushing limits

South Carolina looks at most restrictive abortion bill in the US as opponents keep pushing limits

November 16, 2025
From roadways to classrooms, this New Mexico program is bringing women’s history out of the shadows

From roadways to classrooms, this New Mexico program is bringing women’s history out of the shadows

November 16, 2025
UMFK seeks public input to mark its 150th anniversary

UMFK seeks public input to mark its 150th anniversary

November 16, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • President Trump Downplays Jeffrey Epstein Email Scandal on ‘SNL,’ Offers to Sell Copies of Infamous ‘Blowing Bubba’ Message November 16, 2025
  • Melissa McCarthy to Host ‘SNL’ in December With Musical Guest Dijon November 16, 2025
  • South Carolina looks at most restrictive abortion bill in the US as opponents keep pushing limits November 16, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.