Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Aug 03, 2023

Koscom Adds Crypto Market Data to Investment Data Platform CHECK Expert+

Koscom Adds Crypto Market Data to Investment Data Platform CHECK Expert+South Korean financial IT company Koscom Corp. said Wednesday that it has started offering market data for virtual assets on its investment analysis information terminal service, CHECK Expert+. CHECK Expert+ provides a variety of information and news on foreign exchanges, bonds, overseas markets, and more to professional investors.Photo by Sajad Nori on UnsplashCross-platform data collectionStarting last month, Koscom has been combining the market price information of virtual assets that are scattered across the websites of four major domestic and foreign virtual asset exchanges into one platform on CHECK Expert+. By doing so, investors can now easily compare the current prices of different assets traded on multiple platforms.Cryptos compared with other assetsThrough the terminal, investors can also compare the performance of the popular cryptocurrency Bitcoin with other assets across exchanges such as KOSPI, KOSDAQ, S&P500, NASDAQ, and the US 10-Year Treasuries. This feature allows for more intuitive and straightforward performance comparisons.Given the fact that prices of the same asset can vary depending on the exchange, this service can provide investors with a broader perspective and allow them to make more informed decisions, Koscom said.“This is our first step into virtual asset-related market data services. Leveraging our experience in operating CHECK Expert+ and our expertise in processing capital market data, we aim to provide valuable investment information in the virtual asset market to our users,” said Hwang Sun-jeong, the Executive Director of Koscom.This move by Koscom reflects the growing interest and relevance of the virtual asset market in Korea, and CHECK Expert+ is expected to provide investors with valuable insights in the midst of a rapidly evolving financial landscape.

news
Web3 & Enterprise·

Apr 25, 2025

KuCoin TH enters Thailand’s crypto market

Global crypto exchange platform KuCoin has announced the arrival of “KuCoin Thailand” (to be also known as “KuCoin TH”) in the Southeast Asian country. In a press release publicizing the development, the company outlined that the new platform has been formed following a rebranding of ERX, the first virtual currency exchange to be licensed and supervised by Thai regulator, the Securities and Exchange Commission (SEC).Photo by Bharath Mohan on UnsplashGlobal infrastructure enhancing service deliveryERX has rebranded to KuCoin Thailand, but the exchange will continue to be operated by ERX Company Ltd, while collaborating with KuCoin and benefiting from KuCoin’s global market presence and global exchange infrastructure. Commenting on what KuCoin brings to the partnership, ERX CEO Att Tongyai Asavanund stated: “With the global infrastructure and resources supporting us, we’re enhancing our ability to deliver localized solutions tailored for the Thai market. KuCoin Thailand reflects our continued mission — strengthened by strong technology and a broader global vision.” ERX Board Director Henry Chen said that the objective is “to build a leading digital asset platform in Thailand with global vision, institutional grade service and state-of-art technology.”Southeast Asian expansionFounded in China in 2017, although operating on a global basis, KuCoin continues to have stronger ties to Asia. Following the implementation of restrictions on crypto trading in China a few years ago, the company moved its headquarters to Singapore, subsequently opting to establish itself in the Seychelles. This latest development further strengthens KuCoin’s credentials within the Asian region. In a blog post, the company marked the event as a “key step forward” in its strategic expansion across Southeast Asia. Existing ERX users have already been migrated over to the new platform. The company has placed a notice on its website advising users to download the KuCoin TH app, which has been made available via Android and iOS. Last month ERX announced that it had received approval from the Thai SEC to activate its Crypto Exchange License. The company was first established in Thailand in 2019. It has been under the supervision of the local regulator since 2020.  The ERX platform was originally built out using AlphaPoint white-label software. It received a digital assets exchange license from the SEC in July 2020. ERX parent company, New York-based digital asset management firm Elevated Returns, has been working within the real-world asset (RWA) tokenization arena for some time. In 2018, the company was involved in a $18 million deal to tokenize the St. Regis Aspen Resort, a luxury hotel and resort located in Colorado, United States. Previously, KuCoin had remained unlicensed in Thailand. In recent times, the Thai authorities have made efforts to block unlicensed exchanges from engaging with investors in Thailand. Last month Thailand’s SEC filed a lawsuit against KuCoin competitor OKX for allegedly running an unlicensed exchange. KuCoin Thailand will compete with eight other licensed exchange businesses within the Thai market. These include WAAN Exchange, Gulf Binance, Thai Digital Assets Exchange, InnovestX Securities, GMO-Z.com Cryptonomics, Upbit Exchange, Bitkub Online and Orbix Trade.

news
Web3 & Enterprise·

Aug 04, 2023

Oasys and XPLA to Host Hackathon Promoting Blockchain Interoperability

Oasys and XPLA to Host Hackathon Promoting Blockchain InteroperabilityOasys, a Japanese blockchain gaming platform, has teamed up with XPLA, a blockchain project led by Com2uS, a major Korean gaming company, to hold a hackathon focused on blockchain interoperability. The event, named “Beyond Boundaries,” aims to foster innovative ideas that enhance the seamless connection between different blockchain networks.Photo by Fotis Fotopoulos on UnsplashGlobal participation and prizesAs the importance of interoperability between blockchain networks is growing, Oasys and XPLA have joined hands to host this hackathon. Participants from around the world are invited to compete for a total prize pool of $60,000, with both Oasys and XPLA contributing $30,000 each to reward outstanding solutions.Three areas of blockchain interoperabilityThe event will encourage programmers to address three key aspects of blockchain interoperability. Participants can submit proposals for connecting layer 1 nodes through cross-chain protocols, creating plugin programs to bring games and NFTs to the blockchain, and introducing novel ideas to improve the user experience during the KYC verification process.The hackathon will begin on August 18, with the kickoff event and submissions opening on the same day. Participants will have until August 27 to submit their proposals. The finalist announcement is set for August 29, leading up to the highly anticipated Demo Day on September 3, which will take place at Dreamplus Gangnam, a co-working space for startups, in Seoul.The judging criteria for the competition will focus on the compatibility of the proposed solutions with blockchain technology, creativity, business feasibility, and the progress made in development.Last year, Com2uS became an Oasys validator and has revealed plans to deploy their flagship title, “Summoners War: Chronicles,” as a blockchain game on the Oasys platform.Com2uS has been demonstrating its commitment to the blockchain gaming sector. Recently, the Korean game developer’s venture capital arm, CRIT Ventures, made an investment in blockchain game developer Puzzle Monsters, which gained popularity through AFK MMORPG Idle Ninja Online and action role-playing survival game Ninja Survivors Online.

news
Loading