Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Policy & Regulation·

Aug 26, 2023

Binance Takes P2P Service Measures in Response to Sanctioned Russian Banks

Binance Takes P2P Service Measures in Response to Sanctioned Russian BanksGlobal crypto exchange Binance has removed the option for users to conduct transactions via sanctioned Russian banks on its peer-to-peer (P2P) platform, a decision that comes on the heels of a Wall Street Journal exposé published earlier this week, shedding light on the platform’s involvement in facilitating the movement of funds for Russian users.Previously, Binance’s peer-to-peer service featured five Russian banks under sanctions as a method for ruble transfers between users. However, the company swiftly acted to address potential compliance concerns. Fittingly, this latest news was also broken by the Wall Street Journal on Friday.Dmitry Sidorov on PexelsSailing too close to the windWhen approached regarding the omission of these banks, a Binance spokesperson stated: “We regularly update our systems to ensure compliance with local and global regulatory standards. When gaps are pointed out to us, we seek to address and remediate them as soon as possible.”The Wall Street Journal’s article outlined how Binance’s peer-to-peer platform facilitated ruble-to-crypto trades that frequently involved the sanctioned Russian banks, with Rosbank and Tinkoff Bank being prominent examples.These trades often utilized layers of intermediaries to convert funds from these banks into Binance balances, as detailed by various company resources, user screenshots, and messages in official chat groups. Despite these revelations, Binance’s exchange had continued to handle significant volumes of ruble trading, according to data compiled by digital asset research firm CCData.US DoJ probeBinance’s activities in Russia could potentially contribute to its ongoing legal challenges in the United States. The US Justice Department (DoJ) has been probing the company’s actions for potential violations of American sanctions on Russia. In response to such concerns, the Binance spokesperson emphasized:“Binance aims to diligently comply with the global sanctions rules and enforces sanctions on people, organizations, entities, and countries that have been blacklisted by the international community, denying such actors access to the Binance platform.”WorkaroundsTraders, however, had reportedly found workarounds to the bank removals, as observed in the official Telegram chat group for Russian clients. Many shared that they could still engage with sanctioned banks by selecting alternative payment methods and then manually inputting their Rosbank or Tinkoff bank details.Earlier this year, an investigative report by CNBC alleged that employees of the company had told it that Binance staff regularly helped Chinese customers to bypass Know Your Customer (KYC) controls in order to access the platform. More recently, another report, once again by the Wall Street Journal, found that business in China was booming, which surprised many given that China banned crypto trading within the country in 2021.It’s apparent that the company is reacting to regulatory and legal pressures in taking the decision to make these changes to its P2P service. Perennial crypto critic US Senator Elizabeth Warren took to X (formerly Twitter) on Friday, stating:“I rang the alarm about sanctions evasion by Russia using the crypto platform Binance — and urged [the DoJ] to investigate potentially false statements it made to Congress. We need stronger crypto regulations to rein in illicit finance.“

news
Policy & Regulation·

Sep 28, 2023

Shanghai Court Recognizes Unique Traits of Bitcoin

Shanghai Court Recognizes Unique Traits of BitcoinThe Shanghai Second Intermediate People’s Court has added a layer of legitimacy to Bitcoin despite China’s prevailing anti-crypto stance.In a recently published report, the court recognized digital currencies such as Bitcoin as being unique and non-replicable. It went further still in singling out Bitcoin as being distinct from the thousands of other cryptocurrencies that are currently in existence.Photo by Zhou Xian on UnsplashSun chimes inThe significance of this development has caught the attention of Justin Sun, the Founder of the TRON blockchain network, who took to the X social media platform (formerly Twitter) to share insights from the report. Sun wrote:”The Second Intermediate People’s Court of Shanghai believes that with the development of internet technology, digital currencies represented by Bitcoin possess uniqueness and non-replicability.”Legal attributesDelving deeper into the report’s content, it becomes evident that the court was engaging in a discussion about the legal attributes of Bitcoin and how judicial decisions should be approached in cases involving cryptocurrencies.One striking aspect of the report is how it acknowledges the usage of cryptocurrencies in illegal financial activities, such as illicit fundraising. In this instance, the court has indirectly acknowledged the financial nature of cryptocurrencies, including Bitcoin, despite the fact that a ban has been in place on trading Bitcoin and other cryptocurrencies since 2021.That said, the report also notes that due to the regulatory stance on cryptocurrencies, the legal attributes of digital currencies remain ambiguous, creating challenges in their judicial handling. Despite some courts attempting to disregard the “monetary” and “property” attributes of digital currencies, these efforts have proved unsuccessful.Inherent characteristicsRegarding the monetary attribute, the courts still identify the sale price of digital currencies in their judgments. When it comes to property attributes, these courts struggle to ignore the inherent property value presented by digital currencies during legal proceedings.While acknowledging Bitcoin’s decentralized nature and lack of centralized control, the article still underscores its “major functions of currency,” such as scalability, circulation, storage, and means of payment, making it a global currency.Future implicationsThe legal opinion expressed by the Shanghai court provides a notable boost to the legitimacy of Bitcoin and other digital currencies. It asserts that these tokens undeniably possess value, even if the People’s Bank of China chooses not to formally recognize them.Moreover, the court’s inclination toward classifying cryptocurrencies as personal property aligns with another report from the Chinese courts as well as rulings in other jurisdictions, such as Singapore. Similarly the Shanghai court acknowledges that Bitcoin can be acquired through various means, including mining, inheritance, and buying and selling.The court’s recognition of the enduring value of cryptocurrencies echoes the sentiment that value is a collective human judgment. In this respect, the Shanghai court’s perspective aligns with the reality that many Chinese citizens continue to use digital currencies as a medium of exchange despite the existing ban.The Shanghai court’s unintentional validation of Bitcoin’s unique attributes and value may have broader implications for the legal status and recognition of cryptocurrencies in China and beyond. This latest development could contribute to a more nuanced approach to cryptocurrency regulation and legal interpretation in the future.

news
Policy & Regulation·

Oct 11, 2023

Hong Kong Police Issue Warning as Binance Users Lose Funds to Phishing Scam

Hong Kong Police Issue Warning as Binance Users Lose Funds to Phishing ScamHong Kong has witnessed a surge in phishing scams targeting Binance users, prompting local law enforcement to issue a cautionary advisory.Photo by Serey Kim on UnsplashCyberDefender warningThe warning was issued by Hong Kong police via its CyberDefender Facebook page on Monday. Over the past two weeks, at least 11 Binance customers in Hong Kong fell victim to phishing scams, collectively losing over $446,000 (equivalent to HKD 3.5 million). These scams primarily involve fraudulent text messages.According to Hong Kong police, these fraudulent text messages claim to be from Binance and ask users to verify their accounts by clicking on a link provided within the message. On Facebook, the warning stated:“Recently, fraudsters posing as Binance sent text messages claiming that users must click the link in the message to verify their identity details before a deadline, otherwise their account would be deactivated.”Upon clicking the phishing link and entering their login credentials to “verify” their accounts, victims unwittingly grant fraudsters full access to their Binance accounts. This modus operandi mirrors the tactics commonly employed in phishing scams.CZ chimes inBinance CEO Changpeng Zhao (CZ) also joined in the cautionary chorus, issuing a warning to customers on his X account.The crypto sector in Hong Kong has been facing challenges recently, largely related to the recent JPEX fraud case. The losses incurred from the JPEX exchange scandal have swelled to an estimated $180 million, with over 2,300 victims filing complaints with local authorities.The JPEX scandal led to multiple arrests in Hong Kong and prompted authorities to intensify their efforts against illegal crypto activities. The Securities and Futures Commission (SFC) of Hong Kong introduced regulations mandating the licensing of all crypto exchanges operating within its jurisdiction earlier this year.To date, only two exchanges, HashKey and OSL, have secured licenses under this regulatory framework. Numerous other crypto exchanges in Hong Kong have submitted license applications, but Dubai-headquartered JPEX, despite heavily promoting its application for a Hong Kong license, failed to submit an application to the local regulator. In the wake of the JPEX scandal, the SFC published a comprehensive list of companies seeking crypto licenses and expanded its list of suspicious platforms.Cyber security firm Kaspersky found earlier this year that phishing related to crypto trading is on the rise in Asia, particularly in the Philippines. Binance’s CZ has had to issue warnings where phishing is concerned on previous occasions. He did so in July when the founder of decentralized crypto exchange (DEX) Uniswap was hacked.In February of last year, CZ came out again to warn users of a massive SMS-related crypto phishing scam. Back in 2018 a serious attempt was made to compromise the credentials of Binance platform users via phishing techniques.As phishing scams continue to pose a significant threat to crypto users in Hong Kong, and with the aftermath of the JPEX debacle still reverberating through the industry, vigilance and caution remain paramount for participants in the region’s crypto ecosystem.

news
Loading