Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Jun 01, 2023

Bithumb Shuts Down Crypto Research Center Amid Trading Volume Slump

Bithumb Shuts Down Crypto Research Center Amid Trading Volume SlumpBithumb, a cryptocurrency exchange based in South Korea, is shutting down its research center less than a year after its launch, according to a report by news agency Newsis. The closure is seen as a strategic move to enhance business performance in response to the recent decline in trading volume.Photo by Kelly Sikkema on UnsplashCostly research centersEstablished on June 8 last year, the Bithumb Economic Research Institute is reportedly ceasing operations tomorrow. Research centers are often perceived as costly endeavors, particularly when the company is experiencing poor financial performance. In the traditional financial sector, small and medium-sized securities firms typically prioritize restructuring their research divisions when dealing with profitability challenges.Relevance of research hubsAn official from a Korean cryptocurrency exchange told Newsis that research centers can be a financial burden during times of low trading volumes and subpar performance. Nonetheless, the official underscored the need to furnish investors with refined information through these research hubs, encouraging exchanges to cultivate an environment conducive to informed decision-making based on high-quality data.Since its inception, Bithumb’s research organization has published 55 reports aimed at forecasting cryptocurrency market trends using comprehensive macroeconomic and crypto data analysis. These reports have contributed to drawing investors to the sector.Global restructuring trendThe wave of workforce reductions in the crypto industry isn’t isolated to South Korea; it’s a global phenomenon. Chinese reporter Colin Wu, known for his crypto news platform Wu Blockchain, shared via Twitter that Binance, the world’s largest cryptocurrency exchange, is planning to lay off roughly 20% of its staff, totaling about 8,000 employees.In response to these concerns, Binance CEO Changpeng Zhao, also known as CZ, wrote a tweet yesterday. According to CZ, employee layoffs are a weekly occurrence within the company, based on considerations such as alignment with corporate culture. As an example, he mentioned the remote work environment and how it may not be suitable for everyone. However, CZ reassured that Binance remains engaged in hiring, with a focus on enriching its talent pool.

news
Policy & Regulation·

Jun 02, 2025

Thailand’s SEC moves to block five exchanges to protect investors

Thailand’s Securities and Exchange Commission (SEC), an independent state agency responsible for the supervision of capital markets including the digital assets sector within the Southeast Asian nation, has moved to block five cryptocurrency exchange platforms. In a statement published by the agency to its website on Thursday, May 29, the SEC outlined that it deems the five exchanges, namely OKX, Bybit, CoinEx, XT.com and 1000X.Live, to be unauthorized crypto trading platforms.Photo by REY MELVIN CARAAN on UnsplashCountering money laundering activityIt is acting against these platforms “to protect investors” and to prevent their use for money laundering purposes. In offering services to Thai users on an unauthorized basis, the exchanges were found to be in breach of Thailand’s Digital Asset Business Act B.E. 2561 (2018). The agency has asked the Ministry of Digital Economy and Society (MDES) to take measures to block local access to these online platforms. That block will be put in place on June 28. On that basis, the SEC has advised Thai users of such platforms to proceed to remove their assets from them before that June 28 deadline.  An updated version of the Royal Decree on Measures to Prevent and Suppress Technology-related Crime, (No. 2) B.E. 2568 (2025), was introduced by the Thai government in April. It facilitated the establishment of the Committee for the Prevention and Suppression of Technological Crime.  Following practices overseasThe committee met with the MDES in April, with the parties setting out the process through which unauthorized digital asset platforms would be restricted and blocked. On that occasion, similar practices carried out in other jurisdictions within the Asian region were referred to.  In December 2023 India’s Financial Intelligence Unit (FIU) moved to block nine offshore crypto exchanges, having issued them with compliance show-cause notices.  In April 2024 the Philippines SEC requested that Google and Apple remove apps associated with global exchange Binance from the local versions of their application stores. Japan’s Financial Services Agency (FSA) similarly ordered both companies to remove apps belonging to unregistered crypto exchanges in February of this year. Back in March, the Thai SEC filed a lawsuit against Aux Cayes FinTech Co. Ltd., an OKX affiliate company. The complaint alleged that OKX had been running an unlicensed exchange in Thailand, and was filed with the Economic Crime Suppression Division of the Thai police force. The SEC outlined on March 21 that a similar criminal complaint had been filed against XT.com. It’s understood that Bybit, CoinEx and 1000X.Live have also been recipients of complaints on the same basis. Earlier this year, the Economic Crime Suppression Division considered taking action against Polymarket, a crypto-based prediction market, on the basis that the platform violated Thailand’s gambling laws, and in doing so, posing a risk to economic and social stability in Thailand. In April 2024, the SEC issued a warning to crypto exchange platforms against the use of misleading advertising, drawing their attention to the fact that advertising of that nature would potentially place those platforms in breach of regulatory guidelines. 

news
Policy & Regulation·

Jun 12, 2023

Legislator Invites Coinbase to Set Up Shop in Hong Kong

Legislator Invites Coinbase to Set Up Shop in Hong KongHong Kong continues to position itself as a favorable destination for the cryptocurrency industry, with the latest evidence of that coming in the form of an invitation to US-headquartered crypto exchange Coinbase to set up a base in the autonomous Chinese territory from one of its legislators.In a bold move showcasing its progressive stance on cryptocurrencies, Johnny Ng, a member of Hong Kong’s Legislative Council, has extended an invitation to Coinbase and other crypto exchanges to establish their operations in the region. Ng took to Twitter on Saturday to express his support and offer assistance to “all global virtual asset trading operators,” emphasizing the potential for stock listing opportunities.This invitation came at the end of a week which saw major industry players like Binance and Coinbase face legal action from the United States Securities and Exchange Commission (SEC).Photo by Ben Cheung on PexelsContrasting approachesHong Kong stands in stark contrast to the cautious approach adopted by many Western countries when it comes to cryptocurrencies. In January 2023, Paul Chan, Hong Kong’s Financial Secretary, reaffirmed the government’s commitment to building a robust ecosystem for crypto and fintech. Since then, Hong Kong has been actively developing regulations and implementing compliance measures to foster the growth of the cryptocurrency industry.Recently, the Hong Kong Monetary Authority (HKMA) announced its intention to lay the foundation for a retail central bank digital currency (CBDC). This initiative, revealed on June 9, aims to explore the benefits of CBDCs as a means of everyday payment transactions and to facilitate customer access to cryptocurrency exchanges.Crypto hub ambitionsNg’s invitation to Coinbase exemplifies Hong Kong’s ambition to become a leading digital hub for the crypto industry. Several crypto exchanges, including OKX and Huobi, have already applied for virtual asset service provider licenses in the region, demonstrating their confidence in Hong Kong’s favorable regulatory environment.Hong Kong’s crypto-friendly approach has also attracted interest from prominent international technology companies. In January, Samsung, the South Korean tech giant, announced plans to launch a Bitcoin futures active exchange-traded fund on the Hong Kong Stock Exchange.Furthermore, reports emerged in mid-February suggesting that Chinese government officials have granted strategic approval to Hong Kong’s pro-crypto initiatives. This recognition from Chinese authorities further underscores the significance of Hong Kong’s efforts in the crypto space and their potential impact on the broader digital currency landscape.Coinbase going globalLong before the arrival of last week’s lawsuit against Coinbase, the company had indicated that it was broadening its horizons. Some weeks back, SEC Chair Gary Gensler appeared on Capitol Hill in Washington, D.C., and Coinbase Founder and CEO Brian Armstrong chose that moment to outline that the company would look to operate overseas if the regulatory environment didn’t change in the US.In the intervening weeks, Coinbase has extended its product offering in Singapore, indicating its interest in establishing a base in Abu Dhabi while obtaining crypto licensing in Bermuda.With its proactive regulation, dedication to fostering industry growth, and growing interest from global players, Hong Kong is poised to become a prominent player in the cryptocurrency world. Despite the ongoing scrutiny faced by Coinbase and other exchanges in the United States, Hong Kong presents an attractive alternative for these companies to expand their operations and tap into the region’s thriving crypto ecosystem.

news
Loading