• bitcoinBitcoin (BTC) $ 80,651.00
  • ethereumEthereum (ETH) $ 2,371.36
  • tetherTether (USDT) $ 0.999803
  • xrpXRP (XRP) $ 1.40
  • bnbBNB (BNB) $ 626.65
  • usd-coinUSDC (USDC) $ 0.999839
  • solanaSolana (SOL) $ 84.57
  • tronTRON (TRX) $ 0.339761
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.111153
  • whitebitWhiteBIT Coin (WBT) $ 59.88
  • usdsUSDS (USDS) $ 0.999827
  • hyperliquidHyperliquid (HYPE) $ 43.15
  • cardanoCardano (ADA) $ 0.258005
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 10.33
  • bitcoin-cashBitcoin Cash (BCH) $ 454.19
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 406.61
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • zcashZcash (ZEC) $ 417.64
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 9.57
  • canton-networkCanton (CC) $ 0.148882
  • stellarStellar (XLM) $ 0.158695
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • the-open-networkToncoin (TON) $ 1.79
  • usd1-wlfiUSD1 (USD1) $ 0.999772
  • susdssUSDS (SUSDS) $ 1.08
  • memecoreMemeCore (M) $ 3.41
  • daiDai (DAI) $ 0.999654
  • litecoinLitecoin (LTC) $ 55.32
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • avalanche-2Avalanche (AVAX) $ 9.35
  • ethena-usdeEthena USDe (USDE) $ 0.999169
  • hedera-hashgraphHedera (HBAR) $ 0.089225
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.949590
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007456
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 0.999910
  • crypto-com-chainCronos (CRO) $ 0.069125
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • bittensorBittensor (TAO) $ 284.00
  • tether-goldTether Gold (XAUT) $ 4,549.20
  • global-dollarGlobal Dollar (USDG) $ 0.999833
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • pax-goldPAX Gold (PAXG) $ 4,548.72
  • mantleMantle (MNT) $ 0.641069
  • uniswapUniswap (UNI) $ 3.34
  • polkadotPolkadot (DOT) $ 1.26
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.063826
  • skySky (SKY) $ 0.080822
  • pi-networkPi Network (PI) $ 0.179835
  • okbOKB (OKB) $ 85.45
  • falcon-financeFalcon USD (USDF) $ 0.997810
  • aster-2Aster (ASTER) $ 0.677561
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pepePepe (PEPE) $ 0.000004
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.27
  • ondo-financeOndo (ONDO) $ 0.325565
  • ripple-usdRipple USD (RLUSD) $ 0.999961
  • usddUSDD (USDD) $ 0.999558
  • bitget-tokenBitget Token (BGB) $ 2.06
  • aaveAave (AAVE) $ 93.42
  • ethereum-classicEthereum Classic (ETC) $ 8.85
  • internet-computerInternet Computer (ICP) $ 2.43
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bfusdBFUSD (BFUSD) $ 0.999400
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • morphoMorpho (MORPHO) $ 2.15
  • kucoin-sharesKuCoin (KCS) $ 8.51
  • algorandAlgorand (ALGO) $ 0.119560
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.097569
  • united-stablesUnited Stables (U) $ 0.999791
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.07
  • quant-networkQuant (QNT) $ 67.61
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • ethenaEthena (ENA) $ 0.107831
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.77
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • cosmosCosmos Hub (ATOM) $ 1.90
  • render-tokenRender (RENDER) $ 1.84
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.033684
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.903884
  • gatechain-tokenGate (GT) $ 7.28
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • worldcoin-wldWorldcoin (WLD) $ 0.242935
  • aptosAptos (APT) $ 0.976788
  • wbnbWrapped BNB (WBNB) $ 759.61
  • stable-2​​Stable (STABLE) $ 0.033806
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • filecoinFilecoin (FIL) $ 0.954731
  • arbitrumArbitrum (ARB) $ 0.118440
  • justJUST (JST) $ 0.084772
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010925
  • pump-funPump.fun (PUMP) $ 0.001843
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.007561
  • vechainVeChain (VET) $ 0.007249
  • beldexBeldex (BDX) $ 0.079936
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • jupiter-exchange-solanaJupiter (JUP) $ 0.184714
  • ousgOUSG (OUSG) $ 115.13
  • ghoGHO (GHO) $ 0.999686
  • xdce-crowd-saleXDC Network (XDC) $ 0.029229
  • usdtbUSDtb (USDTB) $ 0.999931
  • bonkBonk (BONK) $ 0.000007
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • dashDash (DASH) $ 45.25
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • usual-usdUsual USD (USD0) $ 0.998457
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • skyaiSkyAI (SKYAI) $ 0.549508
  • official-trumpOfficial Trump (TRUMP) $ 2.37
  • hash-2Provenance Blockchain (HASH) $ 0.010473
  • clbtcclBTC (CLBTC) $ 76,920.00
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000100
  • siren-2Siren (SIREN) $ 0.755830
  • yldsYLDS (YLDS) $ 0.999824
  • midnight-3Midnight (NIGHT) $ 0.030994
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.51
  • true-usdTrueUSD (TUSD) $ 0.998251
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.750703
  • a7a5A7A5 (A7A5) $ 0.012452
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • megausdMegaUSD (USDM) $ 1.00
  • tbtctBTC (TBTC) $ 70,942.00
  • dexeDeXe (DEXE) $ 10.33
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.208811
  • edgexedgeX (EDGE) $ 1.30
  • euro-coinEURC (EURC) $ 1.17
  • venice-tokenVenice Token (VVV) $ 9.32
  • blockstackStacks (STX) $ 0.229292
  • chilizChiliz (CHZ) $ 0.040994
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • aerodrome-financeAerodrome Finance (AERO) $ 0.449361
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • adi-tokenADI (ADI) $ 4.02
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998747
  • sei-networkSei (SEI) $ 0.059652
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • tezosTezos (XTZ) $ 0.370420
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.395958
  • usxUSX (USX) $ 0.999597
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • spx6900SPX6900 (SPX) $ 0.405754
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • injective-protocolInjective (INJ) $ 3.72
  • sun-tokenSun Token (SUN) $ 0.019239
  • layerzeroLayerZero (ZRO) $ 1.46
  • humanityHumanity (H) $ 0.199532
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • curve-dao-tokenCurve DAO (CRV) $ 0.240793
  • monadMonad (MON) $ 0.030445
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • build-onBUILDon (B) $ 0.351009
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • gnosisGnosis (GNO) $ 133.66
  • ether-fiEther.fi (ETHFI) $ 0.421218
  • kinesis-goldKinesis Gold (KAU) $ 146.49
  • decredDecred (DCR) $ 19.58
  • celestiaCelestia (TIA) $ 0.370655
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • zebec-networkZebec Network (ZBCN) $ 0.003420
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • hastra-primePRIME (PRIME) $ 1.04
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • bitcoin-svBitcoin SV (BSV) $ 16.34
  • unibaseUnibase (UB) $ 0.128444
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • lido-daoLido DAO (LDO) $ 0.377189
  • flokiFLOKI (FLOKI) $ 0.000033
  • conflux-tokenConflux (CFX) $ 0.061732
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • usdgoUSDGO (USDGO) $ 0.999954
  • doublezeroDoubleZero (2Z) $ 0.091056
  • pendlePendle (PENDLE) $ 1.86
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • apenftAINFT (NFT) $ 0.00000032
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Animation Tool Lottie Player Hit by Supply Chain Attack, Causes $723K Bitcoin Theft

0 144

Animation Tool Lottie Player Hit by Supply Chain Attack, Causes $723K Bitcoin Theft

A major security breach has impacted multiple decentralized applications (dApps), with the attack stemming from malicious code injected into Lottie Player, a widely-used JavaScript animation library.

The attack exploited recent updates to Lottie Player’s npm package, specifically in versions 2.0.5 through 2.0.7, where hackers embedded malicious code within JSON files that display animations on websites.

At least one individual has lost 10 BTC (US$723,000) after unknowingly signing a phishing transaction linked to the breach, according to Scam Sniffer, a platform designed to protect users from online fraud.

Blockaid, a cybersecurity platform monitoring the incident, confirmed Wednesday the attackers deployed a fake wallet connection prompt, leading users to the drainer malware “Ace Drainer,” which mimics legitimate connections to deceive users.

According to Blockaid, the hackers added harmful code into Lottie Player’s files, turning these animations into entry points for potential scams. Essentially, when users visited sites with this compromised library, they were shown fake pop-ups asking them to connect their digital wallets.

However, these prompts were controlled by hackers and could grant them unauthorized access to users’ funds.

In response to the attack, LottieFiles’ vice president of engineering, Jawish Hameed, confirmed Wednesday that affected versions were removed from npm, and a safe version (2.0.8) was released.

LottieFiles pointed Decrypt to its public statement regarding the breakdown of events when asked for comment.

Hameed noted the breach involved the GitHub account of a senior engineer, through which attackers pushed three compromised updates in just three hours on Tuesday.

LottieFiles has since revoked all access from the affected developer account and taken further steps to prevent future incidents.

This type of “supply chain attack”—where hackers infiltrate widely-used software that many websites rely on—can have widespread consequences. In this case, the compromised Lottie Player versions were automatically pulled into many sites, making it easier for hackers to reach users.

Decentralized aggregator platform 1inch, one of the main targets of the attack, reassured users on social media that only its web dApp was affected and that the wallet app and core protocols remain secure.

Security compromises in widely used libraries and tools have become a critical issue as hackers exploit vulnerabilities that allow them access to unsuspecting users’ assets.

Earlier this month, a PEPE token holder lost $1.39 million after unknowingly signing a malicious Permit2 transaction.

Edited by Sebastian Sinclair

Source

Leave A Reply

Your email address will not be published.