Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Policy & Regulation·

Jan 20, 2025

Thailand’s SEC considers Bitcoin ETF approval

Thailand’s Securities and Exchange Commission (SEC), the Southeast Asian nation’s securities regulator, is believed to be considering moving towards approving spot Bitcoin exchange-traded fund (ETF) products.  In an interview with Bloomberg, the Thai SEC’s Secretary-General, Pornanong Budsaratragoon, said that the agency is weighing up whether to allow individual investors and institutions to access spot Bitcoin ETFs. Budsaratragoon stated: “We have to adapt and ensure that our investors have more options in crypto assets with proper protection.”Photo by Photo By: Kaboompics.com on PexelsMoving along with global crypto adoptionJanuary 10 marked the first anniversary of the approval of spot Bitcoin ETFs in the United States. Given that the U.S. is home to the world’s largest capital markets, that decision has had an impact internationally. That reality is borne out by one of Budsaratragoon’s comments. She stated: “Like it or not, we have to move along with more adoption of cryptocurrencies worldwide.” While the SEC Secretary-General’s comment suggests that she feels a compulsion to move forward in line with developments elsewhere, that wasn’t the agency’s position in January 2024 following spot Bitcoin ETF approval in the U.S.  Shortly afterwards, the regulator, alongside its regional counterpart in Singapore, outlined that it had no plans to approve the product in Thailand, stating: "The SEC has been following these developments closely but we do not have a policy to allow spot Bitcoin ETFs to be established in Thailand for the time being.” Initial access to overseas productsIn March of last year, the agency had warmed to the Bitcoin ETF product offering to a greater extent, by approving access to such products listed overseas to high-net-worth individuals and institutions. Off the back of that approval, One Asset Management (ONEAM) launched a fund of funds in June 2024, enabling Thai investors to gain exposure to Bitcoin ETFs which had been publicly listed overseas. Back in October, Nirun Fuwattananukul, CEO of Binance Thailand, stated in an opinion piece published by the Bangkok Post that he felt that the Thai crypto market was moving from retail towards a focus on the institutions. He stated:“By allowing more institutional funds to participate, the SEC is enabling a diverse range of investment strategies and helping digital assets gain broader acceptance in the mainstream.” Fuwattananukul suggested that the local regulator had made some changes on Oct. 9, paving the way for institutional-grade mutual and private funds to invest in crypto products. The approval of locally listed Bitcoin ETF products would broaden investor access to digital assets in Thailand, particularly in relation to institutional investors, which is in line with the thinking of the Binance executive. Earlier this month, Thailand’s Deputy Prime Minister, Pichai Chunhavajira, announced that a pilot program was being launched to help foreign tourists pay for goods and services using crypto within the Thai resort city of Phuket.  Meanwhile, former Thai Prime Minister Thaksin Shinawatra expressed a bullish view on crypto in a speech he made in Bangkok last week. Shinawatra called on the country’s institutions to be more open to cryptocurrency, while citing regulatory developments in the U.S. relative to the emerging asset class.

news
Web3 & Enterprise·

Jul 10, 2025

Remixpoint raises $215M to buy Bitcoin, CEO to receive salary in BTC

Remixpoint, Inc., an energy management solutions provider that trades on the Tokyo Stock Exchange (TYO:3825), has announced the raising of $215 million to finance its Bitcoin treasury while the company’s CEO has become the first public company executive in Japan to receive his entire salary in Bitcoin.Photo by Michael Förtsch on Unsplash3,000 BTC targetIn a statement published to X on July 9, the company outlined that it had raised ¥31.5 billion ($215 million). The proceeds will be entirely allocated to Bitcoin acquisition. The company is targeting the accumulation of 3,000 BTC.  As of June 16, the company held 1,051 BTC, valued at around $114 million. At today’s pricing, the funds raised would allow Remixpoint to buy a further 1,977 BTC. However, the firm warned that actual acquisition volume may vary depending upon Bitcoin pricing over a certain period of time, combined with the firm’s share price. Providing its justification for the funds raised, Remixpoint said that the decision reflected its “conviction in Bitcoin’s future,” a view that the company has formed following extensive internal discussion. Remixpoint initiated this treasury strategy in September 2024, compelled to do so due to concerns about the Japanese yen, with a desire to hedge against its depreciation. In addition to Bitcoin, the company has also bought altcoins such as Ether (ETH), Solana (SOL) and Dogecoin (DOGE). Japanese firms buying BitcoinRemixpoint is one of a growing number of Japanese firms to establish crypto-based treasuries. Japanese fashion retailer ANAP Holdings held 200 BTC as of July 8, with plans to acquire over 1,000 BTC by August. Publicly listed marketing business Agile Media Network stated in April that the company would make an initial purchase of ¥10 million worth of Bitcoin on a trial basis in an effort to determine if it's worthwhile to invest in the asset on a broader basis. Earlier this year, Japanese gaming firm Gumi announced plans to build up a Bitcoin treasury worth in the region of ¥1 billion. In recent months, SBC Medical Group, nickel processing firm S Science and textile manufacturer Kitabo have either added Bitcoin to their balance sheets or announced plans to do so. Japan’s standout Bitcoin treasury company is Metaplanet, a former hotel operator. Earlier this week, it emerged that the company aspires to build up a 210,000 BTC treasury. Furthermore, it plans to use its Bitcoin holding to buy cash-producing businesses, with a digital bank being one of its potential acquisition targets. On July 8, Remixpoint announced that it had taken the decision to pay the entire salary of its recently-appointed CEO, Takashi Tashiro, in Bitcoin. Tashiro will become the first Japanese CEO of a publicly-listed company to receive his salary in Bitcoin. Remixpoint said that it had taken this decision as part of a shareholder-perspective management outlook. In a tongue-in-cheek comment on X, market analyst Caleb Franzen said that "Now that the Remixpoint CEO is taking their salary in Bitcoin, I think Satya Nadella [CEO of Microsoft] will do the same any day now!" The emergence of crypto treasury firms has faced criticism. However, Elliot Chun, a partner at Architect Partners, asserted back in March that by 2030, a quarter of S&P 500 firms will have invested in Bitcoin.

news
Policy & Regulation·

Jan 11, 2024

Apple India blocks eight exchanges subject to FIU notice

It emerged on Wednesday that the Indian version of the Apple App Store has blocked access to eight crypto exchanges that were recently subject to a show cause notice from an Indian government agency, the Financial Intelligence Unit (FIU). The development occurred only two weeks after these global firms were flagged for allegedly operating "illegally" in the country. The FIU had cited non-compliance with India's anti-money laundering rules. In its statement on Dec. 28, the FIU urged India's IT Ministry to block the websites of all nine services in the country. The affected exchanges include Huobi, Gate.io, Bittrex, Binance, Kraken, Kucoin, MEXC Global and Bitfinex. Binance acknowledged the issue in a social media post, stating that it will continue to work with local regulators. Interestingly, Bitstamp, another exchange mentioned by the FIU, remained operational on the App Store in India. While these apps have been removed from the Apple App Store, they are still available on the Google Play Store in India and their websites remain accessible within the country. Users who had previously installed these apps on their devices can still access them. Photo by Naveed Ahmed on UnsplashTax avoidanceThe backdrop for this action involves a trend where many Indian traders had shifted to global cryptocurrency platforms rather than native digital asset exchanges. India initiated cryptocurrency taxation last year, imposing a 30% tax on gains and a 1% deduction on each crypto transaction.  While Indian-based exchanges like CoinSwitch, CoinDCX and WazirX maintain compliant know-your-customer verifications, global platforms have not followed suit. Notably, WazirX has experienced a drastic 97% drop in trading volume over two years as many traders migrated to global apps. It’s thought that as many as five million crypto users have shifted their trading activity to offshore exchanges. The tax has proven to be controversial and according to Dr. Vikash Gautam, the author of a report on the tax measure published last November, “it just isn’t enforceable . . . It is possible to be done with international cooperation, but we do understand it is a long process. Some of the other countries have some arrangements with international exchanges to track that." Leveling the playing fieldIt’s amid that competitive backdrop that native Indian exchanges lobbied the Indian government through the Bharat Web3 Association (BWA) to take action against unregulated offshore exchanges recently. CoinSwitch's co-founder and CEO, Ashish Singhal, urged offshore exchanges to comply with local regulations, suggesting registration with the FIU and adherence to India's Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) measures. Singhal, whose CoinSwitch platform is a founding member of the BWA industry advocacy group, highlighted that this would not only benefit offshore exchanges but also enhance consumer protection in India through increased regulatory oversight. Earlier warnings from Indian cryptocurrency exchanges foresaw users shifting to decentralized exchanges or non-compliant services due to the New Delhi government's taxation policy on crypto. In response, CoinDCX announced incentives for customers transferring their crypto assets from global exchanges to its India-based platform. Taking to social media on Wednesday, CoinDCX founder Sumit Gumpta stated:”This is a defining moment for [virtual digital assets] in India, and we're dedicated to facilitating a seamless and secure transition for investors navigating these changes.”   

news
Loading