Breaking
February 22, 2025

Lottie Player hit with a supply chain attack, stealing 10 wrapped BTC from Avalanche wallet Hristina Vasileva | usagoldmines.com

Lottie Player was hit with a supply chain attack, affecting one wallet with 10 Bitcoin (BTC). The WordPress tool has been abused to send malicious links to Web3 users, effectively draining wallets. 

Lottie Player, the WordPress animation library, has been used as a vector of attack for Web3 users. Through malicious links, at least one wallet has been drained of 10 Bitcoin (BTC). 

The Lottie Player attack has affected widely used projects like 1inch and Mover. The 1inch attack may be especially harmful, as the DEX trading service is among the most widely used ones on Ethereum. 

Blockaid has also reported it has been spreading malicious wallet connections through its website. Bubble was another front-facing website affected by the malicious popups, and became one of the first to be reported. Bubble is also the source for building third-party apps, which could have been affected in the hours when the old versions were active. 

Researchers from Blockaid have identified Ace Drainer as the most probable source of the attack. The malicious version of Lottie Player has been removed, but not before spreading fake links for signing with widely used Web3 wallets. The attack has been active for at least 12 hours, increasing the balances in several identified attack wallets.

Lottie player hit with a supply chain attack, stealing 10 wrapped BTC from Avalanche wallet
Lottie Player launched a popup asking to connect a crypto wallet. | Source: GitHub

The attack was first noted when a wallet got drained of 10 BTC, leading to the source of fake links. The risk was in quickly signing all requests, including permanent access to wallets. This allowed the attackers to even drain Avalanche C-Chain addresses, stealing a form of wrapped BTC. The attack itself did not ask for a self-custodial Bitcoin wallet, but relied on the need for Web3 connectivity.

Users also noted the Lottie Player would populate a Web3 route with a malicious transaction when used for websites in the usual way. Analysts noted the attack targeted Ethereum and EVM-compatible chains. 

The attackers’ addresses continue to show activity, affecting small holdings of various Web3 tokens. For now, the entire size of the attack has not been accounted, and may have affected other tokens. The attackers are swapping the tokens quickly through Uniswap, or even through MetaMask swap.

Lottie Player attack spread to multiple sites

The Lottie Player attack displayed a very familiar screen for Web3 users, urging them to connect some of the top wallets, including MetaMask, WalletConnect, and others.

Even the TryHackMe platform experienced the popup, but moved to an older version. The issue has been reported by other users of popular websites. 

The attack affected two versions of Lottie Player, first noticed late on October 30. The attacks originated from versions 2.0.5 or higher. Website owners had to clear the attack themselves in the initial hours, by reverting to other tools or older versions of Lottie Player. Some have chosen to delete the scripts as a precaution. 

Wallet owners may still have to revoke permissions, if they have connected to any of the injected links. Sites like 1inch draw in more than 590K monthly users, and may have affected multiple undetected wallets.

Lottie Player team publishes safe version

The Lottie Player team reacted by uploading a legitimate new version 2.0.8, while unpublishing the contaminated scripts. The team noted the faulty versions were three in total, published directly to NPM using a compromised access token from a developer with the required publishing privileges. The team notes no other repositories or libraries have been affected. 

Lottie Player is widely used for animations and minor features on websites, but has been added to the list of distributors for malicious links. Those types of attacks target individual wallets, adding to the risk of poisoned addresses, direct targeting in email and messages, and fake website versions. 

The attack happens during the next stage of a crypto bull market, accelerating attempts to steal more valuable tokens. Connecting a wallet is best done for a specific purpose, avoiding full-time permissions for signing transactions. Launching a wallet connection immediately after entering a website may be a red flag.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Crypto News | Bybit Announces Recovery Bounty Program: 10% of Stolen Funds George Georgiev | usagol...

Crypto News | Financial Damages from LIBRA Coin Fiasco Revealed in Nansen Report Wayne Jones | usag...

Litecoin (LTC) Faces 25% Crash? Traders Brace for a Sell-Off Chandan Gupta | usagoldmines.com

Myanmar Prime Minister hacked on X to launch a meme coin Jai Hamid | usagoldmines.com

Ethereum dominates RWAs with $4.1B in AUM value and 54.5% market share Collins J. Okoth | usagoldmin...

2 Bullish Altcoins Predicted to Outperform Ethereum in February 2025 Cryptopolitan Media | usagoldmi...

Mynamar prime minister appears to be hacked, promoting national coin Hannah Collymore | usagoldmines...

McCann’s Meme Street Revolutionizes Institutional Meme Coin Investing. $MEMEX Likely to 100x as a Re...

Bitcoin’s Bullish Case Hinges On $94,645 Support: Will Buyers Step In? Semilore Faleti | usagoldmine...

Binance’s Changpeng Zhao Flags Security Risks After $1.4B Bybit Hack Mustafa Mulla | usagoldmines.co...

Strategy’s Michael Saylor Calls On The US Government To Buy 20% Of Bitcoin Supply Brenda Ngari | usa...

Key Reasons Why Ethereum Is ‘Destined’ To Rocket Past $10,000 This Cycle — Analyst Brenda Ngari | us...

Ripple’s RLUSD Stablecoin Achieves Major Milestone As XRP Ledger Outshines Ether Amid Rising Adoptio...

Ethereum Faces 7% Drop After Bybit Hack: Can Recovery Hold? Arslan Butt | usagoldmines.com

Bitcoin Faces Serious Price Compression – What Happened Last Time Sebastian Villafuerte | usagoldmin...

Crypto News | ChatGPT and DeepSeek Analyze Ripple’s (XRP) Price Potential for 2025 Jordan Lyanchev ...

Crypto News | Yearly Low in Bitcoin Network Activity Hints at Possible Price Drop to $86K: CryptoQu...

Crypto News | Bybit Hack Fallout: Arthur Hayes, Samson Mow Push for Ethereum Rollback Jordan Lyanch...

Crypto News | Beyond memes: Memecoins with utility value Shane Neagle | usagoldmines.com

Bybit Hack Update: Massive ETH Transfers & User Withdrawals Explained Zameer Attar | usagoldmine...

Crypto firm BitFuFu acquires data center in Oklahoma for $20M Owotunse Adebayo | usagoldmines.com

Mutuum Finance (MUTM) at $0.01: Why Analysts Are Recommending It for 2025 Cryptopolitan Media | usag...

Crypto Market Hit Hard as $566 Million Liquidated After $1.4B Bybit Hack Mustafa Mulla | usagoldmine...

Ethereum Rollback Riddle: Reversing a $1B Heist or Upholding Immutability? Debashree Patra | usagold...

Billionaire investor Novogratz credits XRP army’s role in token’s longevity as SEC drops key crypto ...

DOJ extradites Brazilian to the United States over $290M crypto fraud scheme Owotunse Adebayo | usag...

BlackRock Bitcoin ETF Surpasses 50% Market Share Despite Sell-off: Will This Send the Price Soaring?...

SOL Price Dropped 13% This Week Amid Milei Meme Coin Rugpull: What’s Next? Arslan Butt | usagoldmine...

Largest Crypto Hack Ever : The Story Behind Bybit’s $1.4 Billion Hack Qadir AK | usagoldmines.com

Polygon (MATIC) and Mutuum Finance (MUTM): 2 Long-Term Tokens You Must Have Cryptopolitan Media | us...

Cardano Must Hold Critical Support Around $0.67 To Sustain Bull Run – Details Sebastian Villafuerte ...

Best Crypto to Buy as Odds of a Kanye West Meme Coin Spike 83% Krishi Chowdhary | usagoldmines.com

Crypto News | BTC Price Analysis: Where Is Bitcoin Headed After $100K Rejection? CryptoVizArt | usa...

Crypto News | XRP Breakout Imminent? Ripple Price Analysis Suggests a Decisive Move CryptoVizArt | ...

Crypto News | Crypto Markets Shed Over $100B as BTC Slumped to $95K (Weekend Watch) Jordan Lyanchev...

Arthur Hayes Calls for Ethereum Rollback After $1.4B Bybit Hack – Is ETH’s Reputation at Risk? Musta...

XRP News: Ripple CEO Reacts to SEC’s Decision to Dismiss Coinbase Case Qadir AK | usagoldmines.com

TRUMP Coin Price Collapse Imminent? Risks Rise Amid Bearish Chart Signals, Dilution Fears  Joel Fran...

SUI Forms Double-Bottom Pattern – Is This the Start of a Huge Breakout?  Michael Davis | usagoldmine...

SEC Concludes Investigation into NFT Marketplace OpenSea, Founder Says Ruholamin Haqshanas | usagold...

ZachXBT Identifies North Korea’s Lazarus Group Behind $1.46B Bybit Hack, Arkham Confirms Ruholamin H...

Trump’s Tariff Plan Could Save Average American Over $134K in Lifetime Taxes, Study Finds Ruholamin ...

Black Pass Users Gain Early Access to Astra Nova’s AI-Driven RPG and Ecosystem Perks Cryptopolitan M...

PEPETO and Dogwifhat Eyed by Investors as the Next 100x Memecoin But Which is More Promising? Crypto...

FTX Repayment Strategy: Why Creditors Are Doubling Down on Solana Qadir AK | usagoldmines.com

Gary Cardone Offloads 30,000 XRP at $2.71: Believes ‘XRP Army Won’t Get Stupid Rich’ Anjali Belgaum...

Indian man arrested for purchasing and distributing drugs using crypto Owotunse Adebayo | usagoldmin...

Lazarus starts laundering the 400,000 Ether it stole from Bybit Jai Hamid | usagoldmines.com

Alternative to Solana (SOL) Poised to Reach $4, Currently Available for Only $0.01 Cryptopolitan Med...

Bitcoin’s Grip Tightens — CZ Says There’s ‘No Escape’ From Crypto Christian Encila | usagoldmines.co...

Here’s How the Bybit Hacker Stole $1.5B Worth Ethereum? Zameer Attar | usagoldmines.com

As Bitcoin Sell Pressure Fades, Could A Local Bottom Be Forming? Analyst Explains Ash Tiwari | usago...

Crypto News | DOGE Could Still Surge to $3 if it Holds This Key Support Line: Analyst Jordan Lyanch...

Crypto News | Report: Kaito, SEI, YAP, and Grok Dominate Crypto Trends Amid Market Growth Wayne Jon...

Crypto News | Pi Network Tanks After Mainnet Launch, Analyst Says Solaxy Could Rally Felix Mollen |...

Crypto News | Analyst Tips Bitcoin for $150,000 in 2025 as Expert Says BTC Bull Token Can Help Capi...

Crypto News Today (Feb 22nd, 2025): Bybit Exploitation Sends Shock Waves to Bitcoin & Ethereum S...

Biggest Crypto Hack Ever: North Korea’s Lazarus Group Steals $1.5B from Bybit! Debashree Patra | usa...

Bitcoin Whales’ Profits Plummet! Is the Bull Run Losing Steam? Vignesh S G | usagoldmines.com

North Korean Lazarus Group Behind $1B Bybit Hack – Arkham Intelligence Mustafa Mulla | usagoldmines....

Analysts blame deregulation for $1.5 billion Bybit hack Jai Hamid | usagoldmines.com

Trump revives tariff probe over foreign digital taxes on US Tech Nellius Irene | usagoldmines.com

US stock market crashes in its worst day since 2024 Jai Hamid | usagoldmines.com

Altcoins Ready For Round Two? CryptoQuant CEO Says Altseason Already Begun Rubmar Garcia | usagoldmi...

Crypto News | This Crypto Asset is Dominating the RWA Space Even Amid the Market Drawdown Mandy Wil...

XRP Price Prediction For February 22 Anjali Belgaumkar | usagoldmines.com

Pi Network Clears the Air After Bybit CEO Calls It a Scam, Pi Coin Rises by 20% Mustafa Mulla | usag...

Kanye West will launch his memecoin YZY next week Noor Bazmi | usagoldmines.com

NATO’s Turkey is still interested in joining the BRICS Jai Hamid | usagoldmines.com

XRP Bulls Need This Break For A Shot At $6 Jake Simmons | usagoldmines.com

Pi Coin Price Prediction: Analyst Says 10x Gains Soon Anjali Belgaumkar | usagoldmines.com

Ethereum’s Vitalik Buterin Takes a Moral Stand Against Crypto Casinos Troy Watson | usagoldmines.com

Remittix ICO Soars Past $12.6M Raised After Drawing XRP, XLM Comparisons, Is It The Best Crypto Pres...

Crypto News | Bitcoin price steadies as large holders curb profit-taking in February Andjela Radmila...

Bybit gets 350k withdrawal requests following the hack, receives 40,000 ETH loan from Bitget Noor Ba...

‘Demolish the Ministry of Finance!’ protest erupts in Tokyo, angry attendees say ‘we are not your AT...

Bitfinex Whale Activity Increases As Bitcoin Approaches $100k—Further Surge Ahead? Samuel Edyme | us...

Cardano (ADA) Price Prediction for February 22 Chandan Gupta | usagoldmines.com

SEC closes investigation into NFT marketplace OpenSea Nellius Irene | usagoldmines.com

Is It Time To Buy XRP? TD Sequential Says Yes Keshav Verma | usagoldmines.com

Crypto News | Kraken, Crypto.com among exchanges planning stablecoin launches in EU Assad Jafri | us...

XRP Price Today: How $2.50 Level Could Decide Its Next Move Chandan Gupta | usagoldmines.com

Outspoken crypto critic says BTC is fool’s gold, not worth investing in Nellius Irene | usagoldmines...

Crypto News | Bitcoin Price Crashes on Reports of Alleged $1.5B Bybit Security Incident Jordan Lyan...

Crypto News | Acre Raises $4M at $90M Valuation, Unlocking Bitcoin-Native Compounding for BTC Holde...

Crypto News | BTC Rejected at $100K After $1.5B Bybit Hack, SEC to Halt Coinbase Lawsuit: Your Week...

Crypto News | Bitcoin Joins Altvest Capital’s Balance Sheet in Landmark Treasury Strategy Shift Cha...

Crypto News | Sam Bankman-Fried’s Legal Hail Mary: Denial, Deflection, and a Plea for Pardon Chayan...

Crypto News | 6 Reasons Why This Finance Expert Dumped His Ripple (XRP) Holdings Dimitar Dzhondzhor...

Crypto News | SEC Faces Critical Deadlines in Major Crypto Cases as Agency Shifts Direction Martin ...

Crypto News | Bybit Hack Aftermath: Single Whale Liquidated for $46M as BTC Dumps by $4K Jordan Lya...

Crypto News | ByBit Lost 70% Of Ethereum Holdings To Hacker, Says CEO Andrew Throuvalas | usagoldmi...

Crypto News | Base Faces Market Turmoil: Is Coinbase’s Layer-2 Network at a Crossroads? Mandy Willi...

Panic Or Opportunity? Dogecoin Whales Liquidate 100 Million Coins Christian Encila | usagoldmines.co...

Crypto News | 6 Reasons Why This Finance Expert Dumped His Ripple (XRP) Holdings Dimitar Dzhondzhor...

Crypto News | North Korea’s Lazarus Group now using crypto gifts to breach security defenses Oluwape...

Robinhood stock plunges 14% in worst week since August as crypto surge fades Nellius Irene | usagold...

Bybit reports $1.5B hack to the authorities, working to block stolen ETH sales Jai Hamid | usagoldmi...

SafeMoon CTO Thomas Smith Pleads Guilty to Massive Crypto Fraud Scheme Julia Smith | usagoldmines.co...

U.S. Digital Assets Sub-Committee to Hold Hearing on Bipartisan Crypto Legislation Hassan Shittu | u...

Leave a Reply