Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Jul 17, 2025

Binance launches Sharia-compliant staking product

Global crypto exchange platform Binance has launched “Sharia Earn,” a crypto staking product that has been certified as being Sharia-compliant. Sharia-compliant financial products adhere to Islamic law, with sharia law being Islamic canonical law based upon the teachings of the Koran. The product incorporates multi-token staking featuring BNB, Ether (ETH) and Solana (SOL). The product has been built on top of existing infrastructure which Binance had already used to offer “Simple Earn Locked Products” relative to BNB and liquid staking in the case of ETH and SOL. Users of the product can earn staking rewards on crypto assets, while secure in the knowledge that they are investing in compliance with Islamic finance principles.Photo by Kanchanara on Unsplash‘Most meaningful product yet’The new product was announced by the company during a Binance Square Webinar. Binance CEO Richard Teng described it as the firm’s “most meaningful product yet.” He referred to the launch of the product as a defining moment both for Binance and the broader crypto sector. Teng said that “a truly inclusive financial system must respect the values and needs of every community, and that’s the vision behind Sharia Earn.” He added that “Islamic finance’s core tenets—transparency and shared prosperity—are universal,” asserting that these same values are at play in driving Binance. The platform contracted Amanie Advisors, a Dubai-based global Islamic finance advisory service, in order to obtain Sharia-compliant certification for its latest product. Bader Al Kalooti, Binance’s Head of Operations, Marketing & Growth for the Middle East & North Africa (MENA) region, said that “crypto adoption has surged in many Muslim-majority countries, but yield-generating products have remained largely inaccessible due to compliance concerns.” He claimed that the arrival of “Sharia Earn” addresses this issue. While this is Binance’s first Sharia-compliant product, it’s not the first major exchange to enter this market. Last year, Bybit, a Dubai-headquartered global crypto exchange, engaged with ZICO Shariah Advisory Services in order to obtain certification for the trading of Sharia-compliant digital assets. At the time, Bybit claimed to have launched the world’s first crypto Islamic account. Growing Islamic finance sectorIslamic law prohibits interest-based transactions. Crypto staking can be structured in such a way as to avoid interest. Staking is considered to be acceptable as rewards are not fixed. Staking rewards are seen as profit-sharing, with the staker retaining ownership of the asset and being open to the risk of potential losses. Some forecasts suggest that the overarching Islamic finance sector could reach $4 trillion in the years ahead. That represents a market opportunity for crypto platforms to cater to this market by taking the time to acquire Sharia-compliant certification for their crypto products. Binance and Bitget are not the only entities to spot this market opportunity. A new crypto trading platform called BurjX, founded by Canadian entrepreneurs Adam Ferris and Omar Abbas, has been established in the United Arab Emirates (UAE) with a vision of developing Sharia-compliant and regulatory-compliant crypto products.  While no definitive timeline has been established, Abbas told the UAE English language daily newspaper, the Khaleej Times, that his company “will partner with the appropriate Sharia boards, and when we do launch, it’s going to be approved by the appropriate regulators.”

news
Web3 & Enterprise·

Aug 28, 2023

Hana Securities Holds Second Event to Promote Security Token Venture

Hana Securities Holds Second Event to Promote Security Token VentureHana Securities, the securities arm of South Korean financial holding company Hana Financial Group, is currently holding the second event of its Meta1 project, which aims to bridge future assets with modern finance as part of the company’s security token platform venture.This comes after the first event in April, which was organized in collaboration with the art gallery Print Bakery (PBG), during which it showcased paintings and NFT artwork by PBG exclusive artists Kim Sunwoo and DADAZ.Photo by Zach Key on UnsplashA fusion of NFT art and creative workshopsThe second event, dubbed “Meta1 Art & Play,” is being held in collaboration with PBG again at Airdrop Space in Garosu-gil, southern Seoul, and will continue until September 3. It showcases an art exhibition of 20 works, including new NFT artwork by Kim Sunwoo and DADAZ as well as pieces by collage artist Sunhotan and illustrator Boat. The latter two artists will also teach one-day art workshops for pre-registered guests, and their works will later be issued as NFTs, Hana Securities said.Collaborative pop-ups and diverse eventsIn addition, the event features a pop-up bar jointly operated by Hana Securities and online liquor retailer Dali. Visitors can enjoy a cocktail made with the Johnnie Walker Blue Label Nomad Seoul edition whisky by signing up for Dali and opening a Hana Securities banking account. Johnnie Walker and Dali are participating as sponsors of the event.Visitors who make reservations beforehand will also be eligible to receive a cup of coffee and an NFT made by one of the participating artists. Surprise gifts will also be prepared for 100 guests every day on a first come, first served basis.“We have prepared ‘playable, visual, and enjoyable’ content for visitors to have hands-on engagement in line with the recent trend of experience-based consumption,” said Im Sang-soo, Head of the Wealth Management division at Hana Securities.

news
Web3 & Enterprise·

Feb 20, 2025

Standard Chartered joins with local partners in Hong Kong to launch stablecoin

Standard Chartered Bank Hong Kong, a licensed bank and subsidiary of British multinational banking group Standard Chartered, has partnered with local companies to launch a Hong Kong dollar-based stablecoin in the Chinese autonomous territory.Photo by Chapman Chow on UnsplashJoint venture formed In a press release published by Animoca Brands, a blockchain-based gaming and Web3 venture capital firm based in Hong Kong, the company outlined details of the partnership between it and Standard Chartered, alongside Hong Kong Telecom (HKT), Hong Kong’s dominant fixed-line, mobile and broadband telecommunications firm. The partnership has been structured as a joint venture between the three companies, with the objective of launching the Hong Kong dollar-backed stablecoin. Local regulator and central bank, the Hong Kong Monetary Authority (HKMA) has been working towards implementing a regulatory framework specifically dedicated to stablecoins.  Legislative framework incoming As of the end of 2024, proposed legislation that would enable such a framework had advanced to Hong Kong’s Legislative Council. Before the bill can be enacted into law, the legislative process requires three readings of the bill accompanied by a series of debates and the scrutiny of lawmakers.  Once the legislation has been signed into law, it will require stablecoin issuers to obtain a license from the HKMA. In the case of this particular joint venture, the promoters plan to apply for a license in due course. Standard Chartered is already deeply embedded in Hong Kong’s financial system, making this latest development all the more significant. Alongside HSBC and Bank of China (Hong Kong), Standard Chartered issues the local currency, the Hong Kong dollar. That activity is carried out under the oversight of the HKMA.  The HKMA launched a sandbox environment relative to stablecoins in order to provoke an exchange of views between the regulator and market participants. The three parties to this latest joint venture have been sandbox participants since July of last year, alongside JINGDONG Coinlink Technology and RD InnoTech. JINGDONG declared its intention to launch a Hong Kong dollar-backed stablecoin last year. RD InnoTech plans to launch the HKDR stablecoin in conjunction with HashKey Exchange. Stablecoins ‘starting to eat the world’Earlier this month, Rene Michau, Standard Chartered’s global head of digital assets, set out the bank’s thoughts on stablecoins in an article published on the company’s website and co-authored by Circle Chief Financial Officer (CFO) Jeremy Fox-Green. Within it, Standard Chartered recognized the potential of stablecoins, suggesting that they are key to unlocking a future where blockchain acts as a new “internet of money.” The article went on to state that it is critical for stablecoin issuers “to maintain deep connections with strong banks and for those banks to be building digital asset capability.” The company recognizes that stablecoins are “starting to eat the world,” referring to a global stablecoin circulation that has already surpassed $100 billion.  Evan Auyang, President of Animoca Brands, pointed out that “we are still in the early stages for mass adoption of stablecoins across retail, enterprises and institutions.” He added that Hong Kong has a bright future as a global Web3 hub. Susanna Hui, Managing Director at HKT, believes that “issuing an HKD-linked stablecoin will enhance payment efficiency, streamline transactions, and provide greater security and transparency through advanced Web3 innovations.”

news
Loading