
A security breach involving the 1inch web application has compromised user wallets, as attackers injected malicious code to connect users to a crypto-drainer. 1inch has committed to reimbursing affected users. The breach is linked to a recent update of the Lottie Player npm package, which has been identified as part of a broader supply chain attack. Users of decentralized applications (dApps) like 1inch and others are advised to revoke token approvals and transfer any affected tokens to new wallets to mitigate risks. Additionally, significant transactions involving approximately $9.5 million worth of Ethereum (ETH) have been flagged, originating from addresses connected to the recent security incidents. Users are urged to remain vigilant and follow security measures to protect their assets.
Supply chain attack stemming from JavaScript animation library results in losses for users of 1inch and other platforms October 31, 2024 https://t.co/2kmPoc6lAU
🚨ALERT🚨Our system has flagged significant transactions involving multiple deposits of approximately $9.5M worth of #ETH to @TornadoCash from https://t.co/x8TlCzVqAn Analysis shows that these funds originated from address https://t.co/2HAId00TLK which received 21.1M $USDC on… https://t.co/BP1J8vBOif
DeFi users, stay safe and think about revoking token approvals if you interacted with @RDNTCapital in the past. https://t.co/HCziMrw8nP



