Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Markets·

Dec 06, 2023

Phoenix rises 50% on ADX debut

Phoenix rises 50% on ADX debutDubai-headquartered crypto mining firm Phoenix has debuted on its Abu Dhabi Securities Exchange (ADX). The mining equipment hardware retailer witnessed a 50% surge in its share price following a successful initial public offering (IPO) that raked in $371 million.Photo by Marios Gkortsilas on UnsplashFortuitous IPO schedulingIt emerged last week that the company had adjusted its ADX IPO launch date from Monday to Tuesday to account for the holiday schedule in the United Arab Emirates (UAE) and to “ensure comprehensive participation in the IPO.”That adjustment may have been significant in garnering the level of participation that transpired. Bitcoin and to a lesser extent, the broader crypto market, surged to levels not seen since early 2022. From a low of $876 billion on June 15, 2022, overall crypto market capitalization currently stands at $1.6 trillion.With the Bitcoin unit price having exceeded the $42,000 level on Monday for a time, it’s likely that news of a crypto market resurgence would have aided Phoenix Group’s IPO success on Tuesday morning. In trading on Monday, publicly quoted bitcoin miners such as Riot Platforms, Marathon Digital and CleanSpark had recorded share price gains of between 8 and 11% on the Nasdaq in the United States.Surpassing expectationsTuesday’s trading surpassed the expectations of even the most optimistic analysts, with shares opening at 2.25 dirhams and marking a 50% increase from the IPO price of 1.50 dirhams. The ADX, chosen as the platform for Phoenix’s IPO, was strategically selected due to its alignment with the company’s dynamic vision and the rapidly expanding financial market it offers.The overwhelming response from investors resulted in a 33-times oversubscribed offering, translating into orders totaling $12 billion. The retail portion of the offering experienced an even more astonishing over-subscription rate of 180x.Munaf Ali, Co-Founder & Group MD of Phoenix, sees this milestone not merely as a listing event but as a profound declaration of the Middle East’s ascendance in the global tech and blockchain landscape. He attributes the success of Phoenix’s debut to a burgeoning appetite for financial innovations in the Middle East, underscoring the growing interest in exposure to the cryptocurrency sector among investors in the region.Mining to AI pivotPhoenix’s debut on the ADX occurs at a time when other publicly listed companies in the cryptocurrency sector are reorienting their focus from mining digital currencies to supporting the computational needs of the artificial intelligence (AI) industry. In 2022, the sector generated revenues of $6 billion, a slight dip from the record-breaking year of 2021.Industry analysts, including JPMorgan, posit that the high-performance computing (HPC) sector in AI could prove more profitable than Bitcoin mining. This strategic shift is evident in the rebranding of well-known Bitcoin mining entities such as Riot Blockchain (now Riot Platform) and Hive Blockchain Technologies (now Hive Digital Technologies), emphasizing their diversification efforts.Phoenix, acknowledging the potential of the AI-focused sector, believes it could complement its existing operations and contribute to future growth, aligning with JPMorgan’s forecasts regarding the profitability of HPC in the AI industry.

news
Web3 & Enterprise·

Nov 25, 2023

BingX embarks on rebrand to further service offering

BingX embarks on rebrand to further service offeringBingX, the Singapore-headquartered cryptocurrency exchange platform, has taken the decision to rebrand the business.Improving the trading experienceThe platform, originally known for its role in guiding newcomers into the crypto space through copy trading, claims that the move is designed to elevate the trading experience for users by prioritizing simplicity, efficiency and security.This transformation includes a substantial overhaul of BingX’s visual identity, highlighted by a streamlined logo that caters to the practical needs of traders. The changes extend to the platform’s color palette and typography on digital platforms, all aimed at making the trading process more intuitive and user-friendly.Photo by Patrik Michalicka on UnsplashBroadening market appealWhile initially recognized for its focus on crypto beginners, BingX is now broadening its horizons. The platform introduces advanced features catering to a diverse range of crypto enthusiasts, from novices to seasoned traders. This expansion underscores BingX’s adaptive approach to the dynamic cryptocurrency market, addressing the evolving needs of its user base.Megan Nyvold, Head of Branding at BingX, outlined that the rebranding aligns with the company’s enduring vision of democratizing crypto trading globally, emphasizing diversity and creating professional, user-centric trading environments.From ‘Trading Made Easy‘ to ‘Empowering Traders’In tandem with the visual changes, BingX has also unveiled a new tagline, transitioning from “Trading Made Easy” to “Empowering Traders.” This shift emphasizes the company’s commitment to supporting traders at all levels, ensuring access to reliable and transparent services.In a blog post published by the company on Thursday, Nyvold stated:”Over the past five years, BingX’s vision to build a gateway for the next billion crypto users has been unwavering. As part of this evolution, we have refined our core values with a renewed emphasis on promoting diversity. As we introduce our refreshed brand identity, we reaffirm our assurance of empowering our users, focusing on a more professional and user-centric trading environment that aligns with our vision for collective success.”This latest move is one of a number of ongoing efforts BingX has made this year to further develop the business. In July, the company introduced AstraBit to the platform, an automated algorithmic trading and portfolio management tool, to enhance and automate the crypto trading experience for its platform users.The following month, it introduced a Multiple Deposit Addresses feature to enable greater flexibility and convenience for service users. September brought a collaboration with WunderTrading, adding the use of its automated trading bots to BingX platform users. Earlier this year, the company had integrated crypto portfolio tracker CoinTracking with the platform, in an effort to allow service users to generate reports for tax purposes with ease.BingX was founded in Singapore in 2018 by Josh Lu. The platform claims to have five million service users.

news
Web3 & Enterprise·

Aug 14, 2025

Fonte Capital launches Central Asia’s first spot Bitcoin ETF

Fonte Capital, an Astana-based investment management company that allocates capital across a broad range of asset classes, including digital assets, launched a spot Bitcoin exchange-traded fund (ETF) in Kazakhstan’s capital city on Aug. 13. The firm is based within the Astana International Financial Centre (AIFC), with the launch prompting AIFC Governor Renat Bekturov to take to X to outline that the product offering is the first spot Bitcoin ETF to be listed within the Central Asian region.Photo by Kanchanara on UnsplashReflecting Bitcoin price dynamicsThe product has been listed on the Astana International Exchange (AIX) and has been assigned the ticker “BETF.” In announcing the offering, Fonte claimed that the ETF “aims to accurately reflect the price dynamics of bitcoin, striving to achieve this performance before fees and fund obligations.”Shares in the ETF are listed in U.S. dollars, with the fund having a “non-exempt” classification, meaning that it can be offered to a broad range of investors, including non-qualified retail investors. Each ETF share will be fully backed by Bitcoin, with Fonte having partnered with BitGo for digital asset custody.  Delivering institutional-grade accessTaking to social media, BitGo described the product offering as a “new era for digital assets” in Kazakhstan. The company asserted that through what it termed “U.S.-regulated cold storage,” the new fund is delivering institutional-grade access to Bitcoin within the region for the first time. Fonte pointed out that the fund “provides investors with a regulated and secure way to include Bitcoin in their investment portfolios without the complexities associated with holding and transferring the underlying asset.” This isn’t the first Bitcoin-related product that the AIX has listed. Back in 2021, it listed iX Bitcoin Exchange Traded Notes, with special purpose company iX Bitcoin SPC Limited acting as the note issuer.  The product differs from the Fonte ETF in that it is backed by shares of ProShares Bitcoin Strategy ETF, a future-based ETF first listed on the New York Stock Exchange (NYSE) in 2021. In comparison, Fonte’s product has the advantage of being directly backed by Bitcoin. The ETF’s backers have pointed out that there are further implications for the ETF’s shareholders. As the product is regulated by the AIFC, Fonte asserts that within that jurisdiction, holders of the product’s shares are protected from the potential reach of international sanctions. In this regard, the product offers further protection as it is not dependent upon overseas issuers.  Overall, the AIFC has played a key role in the development of crypto within Kazakhstan over the course of the last few years. In 2023, it awarded crypto exchanges Bybit and Binance approval to trade within the Central Asian nation.  Binance subsequently launched a local crypto exchange platform in Kazakhstan, achieving full licensing in October 2024. In June of this year, the authority granted its first license for the issuance of a fiat-backed stablecoin.  It emerged recently that Kazakhstan is working towards the establishment of a national crypto reserve, with the administrators of the country’s sovereign wealth fund expressing the desire to commence investment in crypto assets.

news
Loading