Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Nov 16, 2023

Blockchain-powered donation platform collaborates with NPO Yana to hold charitable bazaar

Blockchain-powered donation platform collaborates with NPO Yana to hold charitable bazaarCherry, a blockchain-powered donation platform, is set to hold a bazaar with non-profit organization (NPO) Yana at POSCO CHANGeUP GROUND in Seoul from Friday to Saturday. The objective of this event is to support children’s homes and care leavers.Photo by Markus Winkler on UnsplashMedical expense support for children’s homesThe bazaar is being organized by ongoing sponsors of Cherry and Yana. This event will feature sales of corporate-sponsored items, with the proceeds dedicated to assisting with medical and various other expenses at children’s homes and for those who have left care. Visitors can look forward to an array of products from companies like Solideo Systems, Jungsaemmool Beauty, Esther Formula, and Rebuy For You. Moreover, the bazaar will showcase a collection of dresses and cherished items from celebrated personalities, including actresses Shin Ae-ra and Park Jin-hee, comedian Park Na-rae and Kpop singer Sandara Park.In addition to sponsored items, the bazaar will offer a wide range of items, including clothing, shoes, cosmetics, eyewear, and food. A representative from Cherry mentioned that all the vendors have committed to donating a part of their sales proceeds. This arrangement allows visitors to enjoy their shopping experience while also contributing to socially responsible consumption, as their purchases will lead to donations.Attendance at the bazaar is priced at KRW 10,000 (approximately $7.7), and registration for the event is available through the Cherry app. For those unable to attend in person, there’s still an opportunity to contribute by purchasing a ticket, allowing for donations from anywhere around the world.Blockchain transparencyCherry is Korea’s first blockchain-based donation platform, designed to foster a culture of transparent donations by recording all donation flows on the blockchain. Since its inception in 2019, the platform has attracted over 380 donor organizations running more than 1,900 campaigns. The cumulative donations have surpassed KRW 11 billion.Yana allocates 100% of its donations to support projects for children’s homes and individuals transitioning out of care. This commitment to transparency in their donation processes is facilitated through the use of the Cherry platform.

news
Web3 & Enterprise·

Oct 21, 2023

SynFutures Completes Series B Funding Round and V3 Launch

SynFutures Completes Series B Funding Round and V3 LaunchSynFutures, the Singapore-based project behind the SynFutures Protocol and decentralized derivatives exchange (DEX) specializing in crypto perpetual futures, has successfully completed its Series B funding round of $22 million.In a big week for the DEX project, SynFutures also launched V3 of the protocol on public testnet, incorporating its updated automated market maker (AMM) model, Oyster AMM.Photo by micheile henderson on UnsplashPotential token launchThe Series B funding round was spearheaded by Pantera Capital, with participation from Singapore’s HashKey Capital, SIG DT Investments (a unit of the Susquehanna International Group), and other investors.Co-founder and CEO of SynFutures, Rachel Lin, stated that while the company is excited about its recent funding success, it is also open to the idea of launching a native token in the future. However, any such decision would be contingent on market conditions and regulatory considerations.Enabling decentralized crypto derivatives tradingThis Series B funding, which was initiated in 2022, marks a significant milestone for SynFutures, coming to a close nearly two and a half years after its Series A round that raised $14 million in June 2021. In total, the company has now secured approximately $38 million in funding to date. In an interview with The Block, Lin declined to indicate the company valuation associated with the recent funding round.SynFutures, established in 2021, serves as a decentralized exchange catering to the trading of crypto perpetual futures, a derivative product that allows traders to speculate on the future price of cryptocurrencies with leverage and without fixed expiration dates. This approach enables traders to rapidly profit or incur losses based on market price movements.While SynFutures operates on various blockchain networks, it currently ranks as the second-largest derivatives protocol on Polygon, with a total value locked (TVL) of over $6 million, according to data from DeFi Llama. The platform has facilitated over $22 billion in cumulative trading volume since its inception.Notably, SynFutures has introduced its latest platform public testnet version, V3, on the Ethereum testnet. The company aims to extend its support for multiple blockchains, including Polygon and zkSync Era, an Ethereum Layer 2 network, when the mainnet version goes live, scheduled for late this year to early next year. Previous iterations of the platform, such as SynFutures V2 and SynFutures V1, have been deployed on Ethereum, Polygon, Arbitrum, and BNB Chain.V3 FeaturesOne of the standout features of SynFutures’ V3 platform is its proprietary AMM model called Oyster. Lin clarified that Oyster AMM combines concentrated liquidity AMM (offering up to 26,666x boost) with the traditional order book model (providing unlimited liquidity boost).With Oyster AMM, SynFutures aims to compete directly with centralized exchanges. The project’s Chief Marketing Officer (CMO) Mark Lee maintains that the offering provides advantages over other decentralized platforms also. “While several projects, including dYdX, opt for a hybrid approach — integrating off-chain orders with on-chain settlements — the full on-chain methodology stands out for its inherent transparency and trustworthiness,” Lee told Blockworks.SynFutures currently maintains a team of approximately 20 individuals. With the latest funding infusion, the company plans to expand its workforce, particularly in engineering and business development roles, to further its mission of advancing decentralized derivatives trading.

news
Web3 & Enterprise·

Jan 15, 2024

Conan Korea launches open beta service for decentralized storage network

Conan Korea has launched an open beta service for OceanDrive, a desktop platform that contains a network of decentralized computer storage for users to share and explore their digital assets, according to an article published by South Korean news outlet Asia Times on Monday (KST). In comparison to cloud storage, which is subject to service provider policies, has no reward system, and relies on centralized servers, OceanDrive distributes storage across multiple nodes, is equipped with user-controlled access and encryption, and provides incentives for participation and contribution.Photo by Shubham's Web3 on Unsplash"The blockchain market is currently transitioning from NFTs to decentralized physical infrastructure networks (DePIN), which combines digital currency and physical infrastructure. OceanDrive is a platform optimized for the DePIN paradigm and is now making its market debut after four years in development,” explained Pyo Se-jin, CEO of Conun Korea.  Global collaborationThe project aims to create a vast network of storage resources scattered across the globe, all while providing users with cost efficiency, rewards and opportunities for collaboration and sharing of knowledge.  "We hope that this open beta service will give people a chance to experience OceanDrive’s user-friendly system and recognize its difference from cloud storage," Conun Korea said. "We are currently working on implementing OceanDrive into a popular Korean fashion boutique as well as a major online educational institution."      2024 plansThrough this open beta service, the company plans to build a blockchain network infrastructure platform of the highest quality by overcoming the shortcomings of OceanDrive and maximizing its advantages so it can be used not only domestically, but abroad as well.

news
Loading