Skip to content
← Back to newsAce Drainer hacks animation library
Security

Ace Drainer hacks animation library

By ToTo BugelmanNewcomer0 rep· 10/31/2024

The Popular Lottie Player Animations Library Was Hacked

Overview of the Lottie Player Library

Lottie Player is a popular tool used for animations on websites and apps. It allows developers to create engaging visuals easily. However, it recently faced a serious issue when hackers targeted it. This attack was a supply chain attack, which means the hackers got into the system through updates that were supposed to improve the library. They added harmful code to the library's files, turning these animations into entry points for scams. This made it possible for users to be tricked into giving away their personal information or money.

 

Impact of the Hack on Users

The hack had a significant impact on users. Many websites that used the Lottie Player library started showing malicious popups. These popups asked users to connect their digital wallets, but they were actually designed to steal money. One user reportedly lost a large amount of Bitcoin because they unknowingly signed a phishing transaction. Fortunately, the LottieFiles team acted quickly to remove the affected versions of the library and released a safe update.

The attack on Lottie Player shows how important it is to keep software secure. Users must be careful and always check for updates to avoid falling victim to such scams.

 

Details of the Ace Drainer Attack

How the Attack Was Executed

The recent attack on the Lottie Player animations library was a significant security breach that affected many decentralized finance (DeFi) applications. Attackers managed to inject harmful code into the library, which is widely used for web animations. This malicious code created popups on various websites, tricking users into connecting their crypto wallets to a fake service called Ace Drainer. This popup appeared legitimate, leading users to believe they were interacting with a trusted application.

The breach began when hackers gained access to the GitHub account of a senior software engineer at LottieFiles, the company behind the Lottie Player. They quickly released three compromised updates within a short time frame. These updates contained the malicious code that caused the popups to appear on sites using the affected library versions. As a result, users of popular platforms like 1inch and TEN Finance were targeted, with at least one individual reportedly losing 10 BTC, valued at around $723,436 at the time, after signing a phishing transaction.

The attack on the Lottie Player library highlights the vulnerabilities in widely-used software, making it easier for hackers to reach unsuspecting users.

This incident serves as a reminder of the importance of maintaining security in software development and the potential risks associated with supply chain attacks. Users are advised to stay vigilant and ensure they are using the latest versions of software to protect their assets from such threats.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Ace Drainer hacks animation library | BlockzHub