News

Lottie Player Exploit Breaches Crypto Wallet Security, DeFi Apps at Risk

  • Hackers exploit Lottie Player, compromising wallets on trusted DeFi sites like 1inch. Avoid connecting wallets until secure.
  • Updated Lottie Player 2.0.8 cleans the exploit; wallet holders should revoke permissions if linked to affected sites.
  • Attackers used Ace Drainer to hijack wallets. Users should stay cautious with permissions and only connect when needed.

A severe vulnerability in the Lottie Player JavaScript library has compromised numerous websites, including DeFi giant 1inch. The exploit, discovered on October 30, enables attackers to initiate harmful wallet connections, exposing users to potential losses. 

The hack prompts connection requests from popular wallets like MetaMask, WalletConnect, and others. Consequently, users are warned to avoid connecting wallets on suspicious sites until the threat subsides.

Unpacking the Lottie Player Breach

The exploit affected Lottie Player versions 2.0.5 and above, distributing malware-laced popups urging users to connect wallets to fraudulent sites. These malicious popups redirected users to Ace Drainer, a crypto-draining tool specifically designed to empty wallets. 

Unlike past phishing scams that depended on external links, this attack directly infiltrated trusted applications. Major platforms, including TryHackMe, experienced these popups, though they mitigated the risk by reverting to an older version of Lottie Player.

Additionally, LottieFiles reported that compromised versions of NPM were released using a developer’s hijacked access credentials. These versions, embedded with malware, allowed attackers to redirect users to crypto-draining services. Wallet owners who engaged with the hacked links now face potential losses, especially if they fail to revoke permissions.

Swift Response and Updates from LottieFiles

In response, LottieFiles released a clean version, 2.0.8, and unpublished compromised versions. Jawish Hameed, VP of Engineering at LottieFiles, confirmed these infected files had been removed from GitHub. 

The company has since revoked all developer tokens and engaged cybersecurity experts for an ongoing investigation. Importantly, LottieFiles clarified that other resources, like its SaaS services and GitHub libraries, remain unaffected.

Read CRYPTONEWSLAND on google news

Besides containing the breach, LottieFiles advised users to update to secure versions (either 2.0.4 or the latest 2.0.8) immediately. Many site owners responded by deleting compromised scripts, ensuring they do not prompt wallet connections.

Increasing Caution Amid Crypto Bull Market

This breach highlights rising security concerns as the next crypto bull market gains momentum. Wallet security, especially avoiding automatic connection requests, remains critical for users. Blockchain monitoring tool Scam Sniffer documented a $723,000 Bitcoin loss, emphasizing the exploit’s high stakes.

Staying vigilant and adopting minimal permissions for crypto wallets is advised to reduce exposure to future threats. As investigations continue, LottieFiles is expected to release further updates on the breach.

José Gustavo

José is a crypto enthusiast who trades crypto night and day. He loves to share his trading stories and experiences in all his published articles. José likes to hang out and travel to meet new friends. Enjoys sushi, vodka, and tequila.

Recent Posts

6 Affordable Cryptos Under $1 Predicted to Skyrocket in 2024 — The Best Budget Buys for Big Returns

#BRETT, #BOME, #MEW, and #POPCAT may have less short-term potential, #DOGEN stands out for those…

5 mins ago

BNB Battles UNI While Lunex Network’s ICO Surges with Lower Fees and Cashback Rewards

#LunexNetwork, offering cashback rewards and secure non-custodial wallets, is set to dominate the market alongside…

5 mins ago

Whale Insight: New Crypto Under $0.20 Could Replicate XRP’s 2017 Rally and Reach $20 by 2025

#XRP and others show less short-term potential, #DOGEN shines. Designed for those seeking excellence, embodying…

35 mins ago

ADA ‘Boring’ Phase Finally Ending, SHIB Breakout Nears as Lunex Rises with Cross-Chain Interoperability

#Cardano is finally waking up, but the #ADAprice is still miles away from its former…

35 mins ago

MicroStrategy’s Bold Bitcoin Bet Risks Financial Turmoil Says Schiff

#PeterSchiff criticizes #MichaelSaylor's $42B #Bitcoinstrategy, calling it a risky bet that may endanger #MicroStrategy's financial…

55 mins ago

Looking for the Next Big Crypto Opportunity? These Undervalued Cryptos Could Outperform Shiba Inu

#WIF, #MEW, #POPCAT, and #TURBO have less short-term potential, #DOGEN stands out in the current…

1 hour ago