Supply chain
[SC] Supply Chain
[loss] $723,000
"Crypto apps see malicious popups after Ace Drainer hacks animation library"
Primary Source ↗Financial Loss
$723,000
(723,000 USD)
Incident Details
Attackers were able to inject malicious code into the popular “LottieFiles” JavaScript animations library. Visitors to websites using the library saw a prompt to connect their crypto wallets to what was ultimately a cryptocurrency wallet drainer. This affected some crypto platforms that used the library, including the 1inch decentralized exchange aggregator. One victim who connected their wallet suffered the loss of 10 BTC (~$723,000).Other crypto platforms affected included TEN Finance and Movement. Because the animations library is widely used, other non-crypto-related websites also showed the prompt.
Total loss estimated at $723,000.
Technical Details
- Initial Attack Vector
- Software supply chain attack
- Vendor / Product
- LottieFiles
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2024-10-31 Breach occurred
- 2024-10-31 Publicly disclosed