Home web3.0 1inch Users Cautioned Against Any Interactions as Its Website Gets Breached

1inch Users Cautioned Against Any Interactions as Its Website Gets Breached

Oct 31, 2024 pm 12:16 PM
Frontend Supply Chain Attack

Decentralized exchange aggregator 1inch's website has been breached along with multiple other platforms that use the same frontend library, Lottie Player.

1inch Users Cautioned Against Any Interactions as Its Website Gets Breached

Decentralized exchange aggregator 1inch’s website has been breached along with multiple other platforms that use the same frontend library, Lottie Player.

The breach was discovered after users reported suspicious activity on their wallets following interactions with these platforms. Upon investigation, it was found that malicious code had been injected into the Lottie Player, a widely-used animation library used by several dApps and non-crypto websites.

As of now, no user wallets have been reportedly compromised. However, 1inch users are being cautioned against any interactions with the platform until the issue is fully resolved.

According to several posts on X (formerly Twitter), 1inch and TEN Finance are the confirmed victims of this attack so far. However, the number could be much higher, as the exploit targeted Lottie Player versions 2.0.5 and above.

Hackers have reportedly injected malicious code into the front-end JSON files of websites using these versions. This code now enables the compromised sites to perform unauthorized transactions, posing a severe threat to users’ assets and data.

Reports from Blockaid indicate that the attack was introduced through a compromise of Lottie Player’s content server, where a malicious npm package was used to distribute altered code. Blockaid and other security firms have confirmed the injection of unauthorized scripts within the package.

“Legitimate sites (non crypto as well) are now serving malicious content, including anti-debug evasion code. @LottieFiles, it looks like attackers have managed to push malicious versions of your package, with another version being uploaded now,” Blockaid wrote in an X (formerly Twitter) post.

At the time of writing, 1inch hasn’t released any official statement on the breach. However, the Lottie Player team has confirmed that they were able to identify the cause of the breach and are working on removing the affected versions.

Users are strictly advised to avoid connecting wallets or interacting with affected platforms until the security issues are fully resolved.

The above is the detailed content of 1inch Users Cautioned Against Any Interactions as Its Website Gets Breached. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1655
14
PHP Tutorial
1255
29
C# Tutorial
1228
24
'Notorious” Conor McGregor Launches Cryptocurrency Venture, Promises to 'Change the CRYPTO Game” With His $REAL Coin 'Notorious” Conor McGregor Launches Cryptocurrency Venture, Promises to 'Change the CRYPTO Game” With His $REAL Coin Apr 06, 2025 am 10:14 AM

“Notorious nearly never happened. You want the real story? The McGregor story could've been about the lad who never left Dublin. I manifested greatness…”

Nasdaq Files to List VanEck Avalanche (AVAX) Trust ETF Nasdaq Files to List VanEck Avalanche (AVAX) Trust ETF Apr 11, 2025 am 11:04 AM

This new financial instrument would track the token's market price, with a third-party custodian holding the underlying AVAX

Dogecoin (DOGE) Price Plummets 17% Dogecoin (DOGE) Price Plummets 17% Apr 08, 2025 am 11:20 AM

The Dogecoin price plummeted 17% in the last 24 hours to trade at $0.1365 as of 4.30 a.m. EST on trading volume that skyrocketed 271% to $2.24 billion.

Is Wall Street Quietly Backing Solana? $42 Million Bet Says Yes Is Wall Street Quietly Backing Solana? $42 Million Bet Says Yes Apr 10, 2025 pm 12:43 PM

A group of former Kraken executives acquired U.S.-listed company Janover, which secured $42 million in venture capital funding to begin building a Solana (SOL) treasury.

Can BRICS Win from Trump's Tariffs? Can BRICS Win from Trump's Tariffs? Apr 07, 2025 am 11:14 AM

The global economic landscape is continuously shifting, and one of the latest disruptions comes from former U.S. President Donald Trump's imposition of tariffs

Zcash (ZEC) Reaches a High of $35.69 as a Record Amount of Tokens Move Out of Circulation Zcash (ZEC) Reaches a High of $35.69 as a Record Amount of Tokens Move Out of Circulation Apr 09, 2025 am 10:36 AM

Zcash was one of the top gainers during the latest market rally, reaching a high of $35.69 as traders moved a record amount of tokens out of circulation.

TrollerCat ($TCAT) Stands Out as a Dominant Force in the Meme Coin Market TrollerCat ($TCAT) Stands Out as a Dominant Force in the Meme Coin Market Apr 14, 2025 am 10:24 AM

Have you noticed the meteoric rise of meme coins in the cryptocurrency world? What started as an online joke has quickly evolved into a lucrative investment opportunity

MAGACOIN FINANCE Has Gained the Attention of Investors MAGACOIN FINANCE Has Gained the Attention of Investors Apr 06, 2025 am 10:06 AM

XRP is gearing up for a rebound. However, MAGACOIN FINANCE has gained the attention of investors on 4th April, 2025 due to its potential of becoming the next big crypto coin.