Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

May 15, 2024

Liminal expands into Middle East via Abu Dhabi approval

Liminal, a Singapore-based digital asset custodian, has gained regulatory approval in Abu Dhabi, as part of a series of recent steps the company has taken to expand across Asia and the Middle East. Extending digital asset custody to the Middle EastTaking to the X social media platform on May 13, the company outlined that its First Answer Middle East subsidiary received Financial Services Permission (FSP) from the Abu Dhabi Global Market's (ADGM) Financial Services Regulatory Authority (FSRA) on May 9. The approval allows the firm to provide digital asset custody in the region. Liminal had initially been granted in-principle approval last year. In a series of posts, the company outlined that it sees Abu Dhabi’s regulatory framework in respect of digital assets as forward-thinking. It drew particular attention to the work of the FSRA in developing a robust framework to enable institutions to enter the digital assets space.Photo by Sohail Sarwar on UnsplashGame changerOn the actual license approval itself, the company stated, “The FSP license allows Liminal to hold, manage, and safeguard digital assets on behalf of institutions, hedge funds, venture capitalists and professional clients. This is a game-changer for digital asset custody practices in the region.” Further regional expansionOver the course of recent months, Liminal has scored a number of regulatory successes within the Asia Pacific (APAC) and Middle East and North Africa (MENA) regions. Its success within the United Arab Emirates (UAE) has not been confined to Abu Dhabi. In April, First Answer Custody FZE, a Dubai-based subsidiary company, secured initial approval from the emirate's regulator, the Virtual Asset Regulatory Authority (VARA).  Meanwhile, Liminal's Indian subsidiary, First Answer India Technologies, has been established and registered as a reporting entity. As a consequence, it has become the first digital asset custodian registered with India’s Financial Intelligence Unit (FIU), an organization that falls under the umbrella of the Department of Revenue, and  which collects financial intelligence relative to money laundering.  Making further in-roads within the world’s most populous country in November, India’s Central Bureau of Investigation (CBI) appointed the firm with a mandate to manage seized digital assets. Liminal has ties with India insofar as it was founded by Mahin Gupta in 2021, the co-founder of crypto exchange ZebPay. In an interview with CoinDesk, Manan Vora, senior vice president of strategy and business operations at Liminal stated:"We initiated a strategic drive two years ago to secure regulatory licenses in key markets across APAC and EMEA (Europe, Middle East and Africa), strategically positioning ourselves to cater to institutional clients.” Vora added: "Our strategic vision is to expand from our present technology presence in Europe and Taiwan to pushing for regulatory victories there. In Indonesia, we are already working as a technology provider for the nation's sovereign digital asset exchange." Within its home market of Singapore, Liminal was grandfathered into a new licensing system that the city-state introduced recently in respect of digital asset custody as a consequence of already having been a provider of such services in Singapore. The company has been given a grace period of six months. Within that timeframe, it intends to submit an application to local regulator, the Monetary Authority of Singapore. 

news
Web3 & Enterprise·

Jul 18, 2023

P2E Game Covenant Child Developer Partners with Pala for Global NFT Collaboration

P2E Game Covenant Child Developer Partners with Pala for Global NFT CollaborationCityLabs, a South Korean smart city integration platform company, made an announcement today regarding its subsidiary, Metablock, which has entered into a memorandum of understanding (MOU) with Pala, the nation’s largest non-fungible token (NFT) trading platform.Photo by Andrey Metelev on UnsplashGlobal expansionAccording to a report by Newsis, the collaboration between the two companies aims to explore various cooperative efforts in the global development and expansion of NFT projects related to games. To accomplish this, they will utilize the intellectual properties (IPs) of Covenant Child, a global play-to-earn (P2E) game developed by MetaBlock.NFT marketplaceThe initial step of this partnership involves the establishment of an NFT trading platform. MetaBlock recently concluded the final closed beta test for Covenant Child on a global scale. In the upcoming months, the company plans to launch a dedicated NFT marketplace for Covenant Child sometime during the open beta test period. Additionally, MetaBlock will conduct pre-sales of NFTs and list the governance token on cryptocurrency exchanges.Cho Young-joong, CEO of CityLabs, expressed enthusiasm for the partnership, noting that it will provide users with a more convenient and reliable NFT trading environment. Cho further emphasized the company’s commitment to creating an infrastructure that allows users to readily enjoy content developed on MetaBlock.

news
Web3 & Enterprise·

Jan 11, 2024

LINE NEXT launches digital commerce platform DOSI

LINE NEXT, the NFT business arm of Tokyo-based Internet giant LINE Corporation, has officially launched DOSI, a digital commerce platform that allows the trading of digital products like collectible NFTs, according to an official announcement on Wednesday (KST). During its beta period that started in September last year, DOSI was able to attract some 5.5 million users worldwide in more than 180 countries who conducted over 560,000 cumulative transactions.Photo by Jonas Leupe on UnsplashDigital products for everyoneThe company revealed plans to add more than 20 million digital products from over 150 brands including special app memberships, in-game items that are directly verified by game developers, and digital tickets to entertainment performances. There will also be limited-edition products like LINE stamps, digital art and special video playback rights.  Products from popular Japanese brands such as Japan Airlines and CryptoNinja Partners – a 22,222-piece NFT collection – will be available on the service during this month as part of a merging with Line NFT, a comprehensive marketplace for NFTs that has been operating in Japan for a while.  By March, the company will also sell app membership products from more than 20 promising startups, including content community-based social media platform SuperPlat, stock investment platform Quantrack, AI-based music platform inDJ and K-pop fandom community service FL DA. Exclusive membershipIn particular, DOSI also has a special membership called “DOSI Citizen,” which offers points called DON that can be earned by checking app attendance, purchasing products and playing mini-games. DON can be traded for Citizen Items or used to participate in events for a chance to win crypto rewards. Users can easily sign up and log in using their social media accounts and purchase digital products with simple payment methods such as Line Pay, Naver Pay, Apple Pay and Google Pay. Payments can also be made with the digital assets Finsia (FNSA) and Ethereum (ETH). Investment boostLast year, LINE NEXT made headlines for securing the largest investment made in the Asian Web3 industry worth $140 million from a consortium led by Seoul-based private equity firm Crescendo Equity Partners. At the time, the company had divulged that it would use part of the funds to launch DOSI.

news
Loading