Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Nov 01, 2023

Xangle and CryptoTimes partner to advance Web3 adoption in Korea and Japan

Xangle and CryptoTimes partner to advance Web3 adoption in Korea and JapanXangle, a digital asset data research platform based in South Korea, announced Wednesday (local time) a collaboration with Japanese crypto media CryptoTimes with the goal of advancing the widespread adoption of Web3 technology.Photo by Shubham’s Web3 on UnsplashSharing translated reportsThe two platforms have agreed to translate and share each other’s industry analysis reports on their respective platforms. Through this partnership, they aim to bridge the gap between Korea and Japan in sharing Web3 strategies and regulatory updates, which previously faced challenges due to language barriers.As a first step in this joint effort, the Japanese translation of Xangle’s “Waiting for the Spring of Music NFTs: Industry Perceptions and Future Potential” and the Korean translation of CryptoTimes’ “Nike, Adidas and Puma’s Web3 Trend Comparison Report” were made accessible to their platform users on Nov. 27.In particular, Xangle’s reports will be featured in CryptoTimes’ research repository, CT Analysis. Through this, Xangle aims to reach a wider audience in Japan.Stronger communication between Korea and JapanJunwoo James Kim, co-CEO and co-founder of Xangle, shared his excitement regarding their collaboration with CryptoTimes, a renowned media outlet in Japan. He emphasized the significance of both Korea and Japan emerging as leading forces in the Web3 industry within Asia. Kim added that this partnership will foster stronger communication between the blockchain sectors of both nations, accelerating the widespread adoption of Web3.Discussing Web3 development, Kim outlined that we are currently in the third phase, centered around its widespread adoption. The first phase saw the birth of various ideas, while the second phase involved testing these concepts for viability.Shingo Arai, co-founder of Rokubunnoni, which operates CryptoTimes, emphasized that the trends in the Korean Web3 market are not just informational but serve as significant indicators. He noted that sharing reports is merely the beginning. Arai expressed their intent to continuously seek various collaboration opportunities with Xangle, aiming to close the information gap between Korea and Japan in the Web3 arena.

news
Policy & Regulation·

Nov 02, 2023

Exhibition in Goyang City presents blockchain’s use in digital media

Exhibition in Goyang City presents blockchain’s use in digital mediaDigital Media Tech Show 2023 (DMTS 2023) is underway from today, Nov. 2, through Nov. 4 in Hall 4 at the Korea International Exhibition Center, commonly known as KINTEX, in Goyang City. The event gives audiences a chance to explore the present and future of digital content and cutting-edge technologies of the Fourth Industrial Revolution.Photo by Julius Drost on UnsplashFrom smart tech to NFTsThe exhibition explores cutting-edge realms, including smart technology, media and content innovations, extended reality and the metaverse as well as the ever-evolving world of NFTs and blockchain. These technologies not only enhance content creation and distribution but also amplify its value and reach.DMTS is hosted by Gyeonggi Province and Goyang City. It’s organized by KINTEX, the Goyang Industry Promotion Agency and the Korean Commission for Corporate Partnership, with sponsorship from the Ministry of Science and ICT.Last year, the show saw 153 companies display 419 booths and welcomed buyers from 24 countries. The event generated KRW 20.7 billion ($15.4 million) from consultations and KRW 12.1 billion from contracts.Two more simultaneous exhibitionsConcurrently, two other major exhibitions at KINTEX captivate visitors. The Digital Future Show in Hall 5 presents glimpses of future lifestyles, highlighting virtual reality and the metaverse. Meanwhile, Contents Korea in Hall 3 focuses on a wide range of content assets, including movies, games, and music. It also explores their ties to intellectual property, the technologies behind their creation, and marketing strategies. Hosting these shows simultaneously at KINTEX is anticipated to produce a synergistic impact, drawing domestic and international buyers.Lee Dong-hwan, Mayor of Goyang City, underlined the city’s strategic focus on nurturing emerging sectors like video production, content, and drones. He also conveyed his hope that the exhibition would enhance collaboration among top-tier companies and spotlight Goyang as a central gathering place for high-tech businesses.

news
Web3 & Enterprise·

Nov 01, 2023

Planetarium Labs opens pre-registration for Nine Chronicles M

Planetarium Labs opens pre-registration for Nine Chronicles MWeb3 gaming company Planetarium Labs is set to release Nine Chronicles M, the mobile version of its popular game Nine Chronicles, on Nov. 22 at 2 a.m. UTC, accompanied by a global pre-registration event that will run from now until Nov. 21.Photo by Priscilla Du Preez 🇨🇦 on UnsplashNine Chronicle M is a fully on-chain open-source massively multiplayer online role-playing game (MMORPG) — the first of its kind — set against the backdrop of Norse mythology. The PC version of the game has been in development since 2020 and has consistently topped the ranks of dapp store DappRadar’s blockchain game listings with more than 200,000 users worldwide.Bringing Web3 to gamers worldwide“Through this mobile release, users will be able to enjoy Nine Chronicles anywhere at any time,” said Kim Jae-seok, CEO of Planetarium Labs. “We expect to introduce the Web3 experience with an approach that is familiar even to ordinary gamers who are not familiar with blockchain technology by supporting in-app purchases on Google Play and Apple’s App Store.”The pre-registration event will be open to participants all over the world in regions like East Asia, Southeast Asia and Europe. Participants will be eligible to receive various rewards, including up to 10,000 units of the in-game currency Nine Chronicles Gold (NCG), which can be used to purchase in-game items or staked to earn additional rewards. The event will also offer diverse benefits to attract a larger user base through activities such as the Gacha Workshop, which when unlocked presents free rewards like NCG and rare costumes.To overcome the currency exchange-related roadblocks that tend to stand in the way when releasing Web3 games in Korea, Nine Chronicle M’s Korean release will exclude the bridge function that moves NCG to the Ethereum network.High hopes“Nine Chronicles M can play a crucial role in promoting widespread Web3 adoption and is expected to grow as one of the representative games in the idle RPG genre,” said Alan Lau, Chief Business Officer of Animoca Brands, a blockchain firm that invested $32 million in Planetarium Labs during their Series A funding round.

news
Loading