Supply chain [SC] Supply Chain [loss] $723,000

"Crypto apps see malicious popups after Ace Drainer hacks animation library"

2024-10-31 [vendor] LottieFiles
Primary Source ↗
Financial Loss $723,000 (723,000 USD)

Incident Details

Attackers were able to inject malicious code into the popular “LottieFiles” JavaScript animations library. Visitors to websites using the library saw a prompt to connect their crypto wallets to what was ultimately a cryptocurrency wallet drainer. This affected some crypto platforms that used the library, including the 1inch decentralized exchange aggregator. One victim who connected their wallet suffered the loss of 10 BTC (~$723,000).Other crypto platforms affected included TEN Finance and Movement. Because the animations library is widely used, other non-crypto-related websites also showed the prompt.

Total loss estimated at $723,000.

Technical Details

Initial Attack Vector
Software supply chain attack
Vendor / Product
LottieFiles
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-10-31 Breach occurred
  2. 2024-10-31 Publicly disclosed