Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Policy & Regulation·

Oct 18, 2023

Genesis Ordered to Comply with Subpoena in Terraform Labs Case

Genesis Ordered to Comply with Subpoena in Terraform Labs CaseGenesis, the troubled crypto lender and trading company, has been issued a compelling directive by a New York court. The court has mandated Genesis to comply with a subpoena within five days, following a failure to respond to previous requests by the October 9 deadline, relative to a case involving Singapore’s Terraform Labs.Photo by Michael Discenza on UnsplashTerraUSD collapse falloutThese requests are related to the 2022 collapse of the TerraUSD stablecoin, a cryptocurrency which was supposed to maintain a peg to the US dollar’s value until it lost that peg and collapsed. At the time, the demise of TerraUSD reverberated throughout the cryptocurrency markets.In response to this collapse, the US Securities and Exchange Commission (SEC) initiated a legal action against Terraform Labs, the company responsible for the token, and its co-founder Do Kwon, alleging that investors had been misled. Both Do Kwon and Terraform subsequently tried unsuccessfully to have the case dismissed.As part of the progression of this case, the SEC sought to question Do Kwon and gain access to company records held by the Singapore-headquartered firm. The defendants were ultimately unsuccessful in arguing their case in that instance on jurisdictional grounds.Failure to respondJudge Jed Rakoff, in a court order filed on Friday, highlighted Genesis’s non-compliance with the subpoenas, stating:“As of today, the Genesis Entities have failed to produce any documents in response to the Subpoenas.”These subpoenas were issued by the defendants to seek specific information from Genesis Global Capital, Genesis Global Holdco, and Genesis Global Trading on September 12.The court order does not specify the nature of the information sought. It is worth noting that Genesis extended substantial loans to the now-defunct hedge fund Three Arrows Capital (3AC), which was heavily exposed to the TerraUSD stablecoin. In January 2023, three Genesis entities filed for bankruptcy, and its trading arm ceased its US spot market operations in September.In addition to the challenge posed by Genesis’ non-compliance, Judge Rakoff is also wrestling with obtaining information from Do Kwon in connection with the legal proceedings. Kwon’s legal representatives have argued that he cannot physically come to the US as he is serving a jail sentence in Montenegro for possession of a counterfeit passport.However, Judge Rakoff has expressed his determination to ensure Kwon’s availability for cross-questioning and stated that Kwon will not be allowed to provide any declarations in the case without being subject to cross-examination.Citadel under scrutinyIn a related development, it emerged last week that Terraform Labs is accusing American market maker Citadel Securities of having sabotaged its TerraUSD stablecoin. As part of the Singaporean company’s pursuit of justice, it has called upon the United States District Court in the Southern District of Florida to force Citadel to furnish specific documents that relate to their trading activities during the period within which TerraUSD collapsed.Should it fail in that endeavor, Terraform has said that it will look to have the matter heard in Judge Rakoff’s court in New York.This legal development concerning Genesis marks a crucial juncture in the ongoing investigation into the TerraUSD stablecoin’s collapse and the actions of the entities involved, with Genesis now facing increased pressure to cooperate fully with the legal process.

news
Web3 & Enterprise·

Aug 09, 2023

NEOPIN and SBINFT Join Forces to Expand DeFi and NFT Ecosystems

NEOPIN and SBINFT Join Forces to Expand DeFi and NFT EcosystemsNEOPIN, the global CeDeFi platform of South Korean investment holding company Neowiz Holdings, announced today its strategic partnership with SBINFT, the NFT marketplace developer and Web3 subsidiary of Japanese online financial conglomerate SBI Holdings.Photo by Markus Winkler on PexelsExtending their global reachThrough this partnership, the two companies will combine their individual expertise to enhance the global reach of each other’s ecosystems. Their strategy involves facilitating the introduction of established NFT projects from regions such as South Korea, the Middle East, and Southeast Asia into the Japanese market. Additionally, they will collaborate to offer both financial and technical assistance to promising Japanese Web3 initiatives, enabling them to expand internationally.Web3 projects and utility NFTsTo achieve this objective, NEOPIN will onboard a diverse range of Web3 projects to its ecosystem, thereby broadening their adoption and appealing to a worldwide user base. Meanwhile, SBINFT will proactively seek to bring utility NFTs into its NFT marketplace.NEOPIN’s partnership with SBINFT is a strategic step in its plan to enter the Japanese market. Just recently, the South Korean enterprise revealed its proactive approach to intensify endeavors to attract a Japanese customer base.Kim Yong-ki, NEOPIN’s CEO, mentioned that the collaboration with SBINFT represents one of their initial endeavors to penetrate the Japanese market. Kim further stated that NEOPIN is dedicated to achieving favorable outcomes not only within Japan but also across the East Asian region.Ko Jang-deok, CEO of SBINFT, echoed this sentiment, expressing that NEOPIN possesses a robust strategy tailored for the Japanese market. He mentioned that the partnership with such a company will help SBINFT introduce international content to the Japanese market. Ko highlighted SBINFT’s commitment to extending its presence in the East Asian market.

news
Web3 & Enterprise·

Nov 02, 2023

Hivemind Capital Partners expands into Hong Kong market

Hivemind Capital Partners expands into Hong Kong marketHivemind Capital Partners, a prominent player in the world of Web3 and digital asset investment, has officially unveiled its plans for expanding its operations to Hong Kong.Photo by Chromatograph on UnsplashNew Head of Asia appointmentIn a press release published by the New York-headquartered firm on Tuesday, Hivemind outlined that alongside this significant Asian expansion, the company has appointed Stanley Huo as Head of Asia. Huo is a seasoned investment banker with over 15 years of experience at prestigious institutions like China Renaissance, UBS, Citi and BAML across Asia and Europe.Huo expressed his excitement, stating: “I’m thrilled to be joining Hivemind at such a transformative period. The intersection of traditional finance and burgeoning digital asset technologies in Hong Kong presents unmatched opportunities and I’m looking forward to leading our initiatives in this vibrant ecosystem.”Identifying an opportunityHivemind Capital Partners had nothing but praise for Hong Kong as a significant crypto hub. The company highlighted the distinct advantages that come with operating in the city-state, including a well-established ecosystem that facilitates access to traditional financial infrastructure, capital-raising opportunities and the exploration of blockchain-related innovations.Huo told The Block: “It was very interesting to see that the Hong Kong government welcomes all the Web3 capital and talents… They want to build up a Web3 center.”Matt Zhang, Founder and Managing Partner of Hivemind, is equally enthusiastic about the Hong Kong expansion, stating:“Our expansion into Hong Kong not only represents our firm’s growth, but our commitment to being at the center of financial innovation and technology. With Stanley leading our business in Asia, we are positioned to significantly contribute to, and influence, the evolving narrative of blockchain technology and digital assets in the region.”Zhang is a speaker at Hong Kong Fintech Week later this week, where he will participate in a panel discussion titled “The Future of Stablecoins: Exploring Virtual Asset Payment Infrastructure and the Rise of Non-USD Stablecoin Frameworks.” He founded Hivemind in November 2021, with a view towards deploying capital within verticals such as crypto infrastructure, virtual worlds, programmable money and blockchain protocols.Hivemind has been on a significant growth trajectory, as evidenced by its recent launch of a $1.5 billion investment vehicle, with available funds still waiting to be deployed. Additionally, the company introduced the Liquid Opportunity Fund, a $300 million crypto fund, earlier in the year, securing $60 million for the fund in June.Following a regional trendThe company’s move to Hong Kong aligns with the broader trend of cryptocurrency firms recognizing the region’s potential and considering it for their expansion plans. Notably, Zodia Custody, a digital asset custodian backed by Standard Chartered, recently announced its launch in Hong Kong.While Hong Kong has actively positioned itself as a hub for Web3 companies, boasting recent developments like the introduction of retail trading for licensed crypto exchanges in August, it has also faced challenges. The city recently witnessed the largest Ponzi scheme in its history, involving the embezzlement of approximately $166 million from JPEX crypto exchange users. The investigation into this incident is still ongoing.

news
Loading