SlowMist Chief Information Security Officer 23pds posted, Please be aware of poison attacks, users using @solana/web3.js, version 1.95.6 and 1.95.7 can be attacked by thieves who disclose private keys. If your product is using these versions, please upgrade to 1.95.8 (1.95.5 not affected).
SlowMist founder Cosine said that Lottie Player was attacked by supply chain poisoning, and Ace Drainer's phishing gang poisoned Lottie Player, a front-end scripting module relied on by well-known Web3 projects. Fortunately, it was discovered in time, and the impact should not be large. If your project uses the Lottie Player module, check to see if malicious code has been introduced (the current known version 2.0.4 and the latest 2.0.8 version do not have malicious code).
In response to the question of whether accounts were cleared after being poisoned by Tornado Cash-related addresses, OKX CEO Star wrote on the X platform that "for each case, a compliance specialist will conduct in-depth investigation. If it is indeed passive poisoning, it will not affect the use of user accounts." Earlier, Star said that OKX accounts that interact with Tornado Cash's funds will be cleared.