1inch frontend hit by major supply chain attack
Decentralised exchange aggregator 1inch (CRYPTO:1INCH) was compromised in a widespread supply chain attack that exploited vulnerabilities in the popular Lottie Player library.
The breach involved the injection of malicious code into the front-end library, affecting multiple decentralised apps (dApps) and non-crypto websites utilising Lottie Player.
The security incident specifically impacted Lottie Player versions 2.0.5 and above, where attackers embedded unauthorised scripts into JSON files on affected sites.
This malicious code enables unauthorised transactions, posing significant risks to users’ funds and sensitive data.
Security firm Blockaid reported, “Legitimate sites (non-crypto as well) are now delivering harmful content, including anti-debug evasion code.”
Users are strongly advised to refrain from connecting wallets or engaging with compromised websites until the security flaws are fully mitigated.
While no compromised wallets have been confirmed thus far, the situation remains precarious.
According to Blockaid, the attack originated from a compromised npm package, which was disseminated via Lottie Player’s content server.
Reports suggest that the attackers managed to infiltrate the library and push altered versions, targeting crypto platforms like 1inch and TEN Finance.
However, the full extent of the breach remains unclear, with the number of affected sites likely higher.
Lottie Player’s team has identified the root cause and is actively removing the compromised versions.
They urged users to ensure that websites are running either version 2.0.4 or the latest 2.0.8 to guarantee security.
At the time of reporting, the 1inch price was $0.2583.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
New spot margin trading pair — HOLO/USDT!
FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn
- FUN plunged 32.34% in 24 hours to $0.008938, marking a 541.8% monthly loss amid prolonged bearish trends. - Technical breakdowns, elevated selling pressure, and forced liquidations highlight deteriorating market sentiment and risk-off behavior. - Analysts identify key support below $0.0080 as critical, with bearish momentum confirmed by RSI (<30) and MACD indicators. - A trend-following backtest strategy proposes short positions based on technical signals to capitalize on extended downward trajectories.

OPEN has dropped by 189.51% within 24 hours during a significant market pullback
- OPEN's price plummeted 189.51% in 24 hours to $0.8907, marking its largest intraday decline in history. - The token fell 3793.63% over 7 days, matching identical monthly and yearly declines, signaling severe bearish momentum. - Technical analysts cite broken support levels and lack of bullish catalysts as key drivers of the sustained sell-off. - Absence of stabilizing volume or reversal patterns leaves the market vulnerable to further downward pressure.

New spot margin trading pair — LINEA/USDT!
Trending news
MoreCrypto prices
More








