Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Policy & Regulation·

Jan 30, 2026

Startale Group secures another $13M from Sony Innovation Fund

Startale Group, a Japan-based Web3 solutions provider, has secured an additional $13 million investment from the Sony Innovation Fund, which is financed by Sony Group and focuses on backing venture companies. In a press release, Startale said the new funding would deepen its ongoing collaboration with Sony, with a focus on Soneium—an Ethereum layer-2 blockchain built using Optimism’s Superchain technology. Soneium is positioned as the flagship project of Sony Block Solutions Labs, a joint venture between Startale and Sony Group.Photo by Nikita Kostrykin on UnsplashSince launching in January 2025, Soneium has gained traction in the Web3 sector, according to figures cited by the company. Startale said the network has processed more than 500 million transactions over the past year, supports 5.4 million active wallets, and hosts over 250 decentralized applications.  The collaboration is intended to explore how blockchain technology could be applied to intellectual property management, creator monetization, and fan engagement, areas where Sony has an established global presence. Startale launches stablecoin on SoneiumThe ecosystem expanded further this month with the integration of Startale USD (USDSC), a stablecoin built on infrastructure provider M0 and backed by short-term U.S. Treasuries, according to Startale. The token is now live on Soneium, whose ecosystem includes partners such as Aave, Uniswap, and Chainlink.  Users can purchase USDSC through the Startale App, the company said, and use it for in-app trading, yield generation through deposits, and liquidity provision in the Startale USD pool on Uniswap in exchange for STAR Points. Startale’s push comes as more established Japanese companies explore blockchain-based initiatives at home and abroad. Matsumoto, a Fukuoka-headquartered printing company founded in 1932, has outlined a long-term concept to create a digital asset treasury for students, under which student activities would be recorded on the Solana blockchain. The company has said the records would not be used for ranking or evaluation, but instead to encourage learning and support future career opportunities. The company has also described a broader ecosystem in which business profits could be returned to children and their families through a portfolio of cryptocurrencies, positioning the concept as both an educational incentive and a potential source of financial support. Nomura’s crypto arm seeks U.S. bank charterJapanese firms are also seeking to expand their crypto operations overseas. Laser Digital, the crypto arm of Nomura, has applied to the U.S. Office of the Comptroller of the Currency for a national trust bank charter, according to The Block.  If approved, the charter would allow the firm to operate nationwide without obtaining custody licenses on a state-by-state basis, though it would not permit the acceptance of retail deposits. The company is also expected to offer spot crypto trading. Approval would place Nomura alongside firms such as Circle, Ripple, and BitGo, which have received conditional approval from the OCC to operate as federally regulated trust banks, subject to final requirements. 

news
Markets·

May 01, 2025

Crypto fraud hits 20% of Korean investors, global trend shows seniors most vulnerable

A recent survey in South Korea found that 20.3% of crypto investors have fallen victim to financial losses. Conducted by the Korea Financial Consumers Protection Foundation in late December, the survey polled 2,500 adults aged 19-69, with respondents able to select multiple loss categories. Investors in their 60s were most vulnerable, reporting a 25.3% loss rate. Exchange-related problems constituted the majority of incidents (72.8%), followed by online chat room scams (44.7%) and investment fraud (35.5%).Photo by Growtika on UnsplashExchange failures lead lossesAmong exchange-related losses, 40.6% of users couldn't sell assets due to system failures, while 11.5% lost digital assets through exchange hacking. Overall, exchange technical issues accounted for 52.1% of reported losses, with another 20.7% losing assets when exchanges closed completely. Chat group scam victims experienced various forms of fraud: 23.2% paid for worthless or false information, while 21.5% suffered financial losses through market manipulation or proxy trading schemes. Investment scams included fake crypto projects or fraudulent firms (18.0%), deceptive exchanges (10.3%), and other scams (7.2%). Most victims (75.1%) reported losses under 10 million won (approximately $6,945), with 34.6% losing less than 1 million won. Due to these relatively small amounts, 67.7% took no action following their losses. Of the 32.3% who sought help through various channels, 73.9% were unable to fully recover their funds. Problem worsening across Asia and beyondThis problem extends beyond South Korea. In neighboring Japan, police reported 19,038 crypto fraud cases in 2023, with damages totaling 45.26 billion yen (about $300 million), according to Chainalysis, citing Japanese National Police Agency data. These figures surpass 2022 numbers, indicating continued growth in fraudulent activities. A recent case highlighted by the Fukushima Minyu Shimbun involved a Soma City woman in her 50s who lost approximately 116.6 million yen ($780,000) to scammers impersonating police officers. The fraud began with a fake customer service call, followed by deceptive claims about fraudulent accounts and threats of arrest, which led her to create cryptocurrency accounts and transfer funds before eventually reporting the scam. Elderly at highest risk as fraud surgesThe FBI's Internet Crime Complaint Center's 2024 report further confirms this trend, documenting 149,686 crypto fraud complaints in the U.S. with $9.3 billion in reported losses—66% higher than in 2023. Notably, people over 60 were the most affected demographic, consistent with the Korean study's findings.

news
Web3 & Enterprise·

Nov 27, 2023

Metabora Singapore officially launches blockchain-based app for golf fans

Metabora Singapore officially launches blockchain-based app for golf fansMetabora Singapore, a subsidiary of South Korean blockchain game developer Metabora formerly known as Kakao Friends Games, has officially launched BirdieSquad, a blockchain-based community platform for fans of professional golfers in the Korea Ladies Professional Golf Association (KLPGA). This comes after the beta version that was launched in August quickly gained popularity, topping the ranks of sports-related apps.Photo by Splash Pic on UnsplashRevolutionizing the golf fandomBirdieSquad was developed by Kakao VX, the digital sports arm of Korean internet juggernaut Kakao, with the goal of creating an innovative and fun playground for golf fans to interact and create a fandom-based community. Users can own NFTs of their favorite golfers — which come in six tiers: Uncommon, Rare, Super Rare, Epic and Legendary — which are stored in personal wallets, and earn various rewards based on players’ actual performance results. They can also interact with other users and compete in “cheer-offs”. During off-seasons, Metabora plans to host various events such as AI-based championship tournaments.The platform is currently working with 46 professional golfers, including Han Jin-seon, Park Hyun-kyung, Lee Ye-won and Kim Min-byul. The platform said that it would bring more athletes in the future.“As we strive to create a new fandom culture where pro golfers and fans can interact, we will expand our ecosystem by onboarding various entertainment content revolving around gaming and sports,” said Lim Young-joon, Chief Business Officer of Metabora Singapore.Expanding partnershipsMeanwhile, the company has been expanding its partnerships with various global blockchain networks such as Polygon, NEAR Protocol, Ethereum and BNB Chain to expand its global ecosystem.

news
Loading