Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Policy & Regulation·

Aug 23, 2023

Indian Crypto Exchange CoinDCX Implements Workforce Reduction

Indian Crypto Exchange CoinDCX Implements Workforce ReductionIndian cryptocurrency exchange CoinDCX has recently taken the step of reducing its workforce by approximately 12%.The strategic move was announced by way of a statement from CoinDCX founders Sumit Gupta and Neeraj Khandelwal, published to the firm’s website on Tuesday. The cutback is being made in response to the prolonged bear market and the consequences of India’s Tax Deducted at Source (TDS) policy on domestic exchanges.Photo by Hardik Joshi on UnsplashMacroeconomic and crypto market headwindsGupta and Khandelwal described the decision that they’ve taken as being challenging, although they outlined that it was taken with a view toward steering the business to profitability and sustainability amidst trying macroeconomic conditions in the crypto sector.The company has encountered significant headwinds due to the overall tough conditions in the crypto market. These challenges have resulted in decreased trading volumes and revenues for CoinDCX. In light of these circumstances, the company has determined that resizing specific teams within the organization is necessary in order to secure the viability and long-term growth of the operation.71 jobs cutApproximately 71 employees are being affected by the workforce reduction, out of CoinDCX’s total workforce of around 590 based in Mumbai. To mitigate the impact on these employees, the company has implemented a support package aimed at providing comprehensive assistance during this transition.This package includes severance pay equivalent to the full notice period, an extra month of salary, compensation for variable pay and incentives, encashment of unused leave days, extension of health insurance and wellness benefits, and access to counseling support.In spite of the necessity for workforce reduction, CoinDCX’s outlook on the Indian market remains optimistic. The company remains steadfast in its commitment to driving crypto and Web3 adoption to a target of 50 million individuals by 2025.No further reduction plansThe founders emphasized that this reduction is a unique, targeted action and that they have no further plans for team reductions. They claim to have engaged in thorough discussions with senior leaders within the company to ascertain the best path forward, with a commitment to overcoming challenges and reinforcing the company’s foundation.In spite of this setback CoinDCX maintains that its vision is intact, encompassing a presence not only in the Indian market but also further afield.Industry trendCoinDCX’s current struggle has been mirrored by a plethora of leading crypto exchanges over the course of recent months. In July, it emerged that Seychelles-based Kucoin was cutting jobs although the firm’s CEO asserted that it wasn’t a layoff plan and more so a reevaluation of the organization’s structure.Earlier that month, Thai digital asset exchange Bitkub cut its headcount in an effort to manage costs during this period of challenging market conditions. Recently, leading global crypto exchange Binance announced one thousand job losses while stating that more jobs may be cut in the future.The decision made by CoinDCX underscores the broader struggles that startups and businesses within the crypto space face. With the bear market’s impact and regulatory pressures, companies are being compelled to make difficult choices in pursuit of long-term sustainability.

news
Markets·

Jun 09, 2023

Bullish Market Analysis Finding as Asia Doubles Crypto Users

Bullish Market Analysis Finding as Asia Doubles Crypto UsersComing off the back of the last bull run, the crypto sector has been challenged with cooling price levels also affected by global macroeconomic headwinds. Despite that, a recent crypto market study by financial news platform Finbold has found encouragement with a significant increase in crypto users, most notably in Asia.Photo by Jéan Béller on Unsplash37% increase in global usersAccording to the market data presented by Finbold on Thursday, the number of global crypto users has reached 417.5 million as of 2023, representing a year-over-year growth of 36.88%. This translates to an increase of 112.5 million users compared to the 2022 count of 305 million.Several factors contribute to the growth in crypto user numbers. The fear of missing out (FOMO) phenomenon plays a significant role, as individuals see market downturns as an opportunity to enter the market and potentially benefit from their investments.Mainstream adoption and awareness of cryptocurrencies have also attracted new users, aided by the accessibility and convenience of crypto platforms and exchanges. Additionally, the acceptance of cryptocurrencies as a form of payment by businesses has further fueled user growth.In emerging markets with unstable economies and limited access to traditional banking services, cryptocurrencies have been embraced as an alternative and inclusive financial solution, driving adoption in those regions.Standout growth in AsiaAsia leads the way with 260 million users as of May 2023, marking an astonishing 100% growth from the previous year’s figure of 130 million. North America follows with 54 million users, witnessing an addition of 3 million compared to the 2022 count of 51 million.When examining crypto ownership in relation to the population of each country, Thailand claims the top spot in 2023 with a share of 9.32%. India comes in second with 7.23%, followed by Brazil at 6.98%. Pakistan ranks fourth with 6.4%, while France rounds out the top five with 5.9%.Observers believe that regional crypto user trends will be influenced by regulations. Asia dominates the market, driven by the increasing adoption of blockchain-based payment solutions in countries like India, China, Singapore, South Korea, and Japan, particularly within the banking, financial services, and insurance sectors.African & European user declineAfrica experienced a decline of 28%, going from 53 million to 38 million users. Similarly, European users dropped from 43 million to 31 million. Notably, Europe has witnessed a drop in usage, coinciding with the enactment of the Markets in Crypto Assets (MiCA) law, which aims to create a legal framework for the crypto asset market.The growth in global user numbers is remarkable, considering the challenging phase the crypto sector has been going through. High-profile incidents, including the FTX crypto exchange collapse and the Terra (LUNA) ecosystem crash, have eroded trust within the sector. Moreover, the crypto market has had to navigate an uncertain regulatory landscape, with jurisdictions like the United States cracking down on the sector.Lawsuits filed by the US Securities and Exchange Commission (SEC) against Ripple, Binance, and Coinbase for alleged securities laws violations are likely to discourage investor involvement. Regions with stricter regulations, such as North America and Europe, are expected to lose crypto business to the Asia-Pacific region.

news
Web3 & Enterprise·

Nov 08, 2023

GDAC joins hands with Zodia Markets to cultivate global digital asset network

GDAC joins hands with Zodia Markets to cultivate global digital asset networkGDAC, a cryptocurrency exchange run by Korean blockchain-based fintech company Peertec, has signed a business deal with Zodia Markets, a European digital asset marketplace under the UK’s Standard Chartered Group. As key institution-first digital asset platforms in their respective regional markets, the two enterprises plan to work together to build a global digital asset and stablecoin network to drive innovation, with a focus on preventing money laundering and reducing financial costs.Photo by m. on UnsplashAbout Zodia Markets and GDACThe Standard Chartered Group established Zodia Markets in 2021 following approval from the UK’s Financial Conduct Authority (FCA). The group’s latest partnership with GDAC represents a step further into the Korean market, in which it is already a major player through its local branch, the Korea Standard Chartered Bank.GDAC has been making strides in cybersecurity by forging partnerships. The exchange teamed up with Genians, a cybersecurity firm listed on the KOSDAQ stock exchange, and attracted investments from it to accelerate the establishment of a global security network. In October, GDAC entered into a collaborative agreement with crypto wallet provider Bitgo, aiming to enhance the security of the exchange’s wallet services.The exchange serves not only profit-oriented corporations but also non-profit organizations, such as the Community Chest of Korea. It also runs the GDAC Fund Service, a digital asset management solution for corporate clients that it jointly founded with Woori Financial Group.Dedication to different client demographics“Through our partnership with Zodia Markets, a subsidiary of the UK’s Standard Chartered Bank, we look forward to providing even higher-value digital financial services to our corporate clients,” said Lee You-ree, CCO of GDAC. “We also plan to continuously launch helpful, high-liquidity digital financial services for individual customers as well through our work with a European digital financial platform.”

news
Loading