Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Sep 18, 2023

SK C&C Issues Voluntary Carbon Offsets on Blockchain-Based Credit Platform

SK C&C Issues Voluntary Carbon Offsets on Blockchain-Based Credit PlatformSK C&C, the information communications technology arm of South Korean conglomerate SK Group, said last Thursday that it has issued a total of 186,595 carbon offset credits through 19 projects on the blockchain-based carbon reduction certification and credit trading platform Centero.Amidst the ever-growing challenge of climate change, industries and companies around the world are attempting to reduce their carbon output and reach net zero emissions through involvement in carbon finance — specifically, carbon credit markets.Photo by Jas Min on UnsplashUnderstanding carbon marketsThere are two types of carbon markets — the compliance market, which uses a cap-and-trade system, consists of governments and companies that are legally mandated to offset their carbon emissions. On the other hand, the voluntary carbon market (VCM) operates outside of mandatory frameworks and uses a project-based system to allow companies, organizations, and individuals to trade carbon offset credits voluntarily. Each of these carbon offset credits represents the reduction of one metric tonne of carbon dioxide or greenhouse gas (GHG) emissions. Participants in the voluntary market are mainly driven by their corporate social responsibilities, shareholder pressure, or PR motives.Revolutionizing voluntary carbon reductionCentero — short for Center of Net Zero — provides a one-stop registry service that enables monitoring, reporting, and verification of greenhouse gas reduction projects in the VCM, and issues certified carbon reduction credits to support credit transactions with companies that are pursuing net zero goals. It was developed by SK C&C and is currently operated by the KCCI Center for Carbon Reduction Certification according to the KCCI Carbon Standard, which evaluates and certifies carbon reduction efforts.Centero takes care of the entire process of voluntary carbon reduction projects, from preparation to registration and execution, credit certification, and credit distribution. Its advantage also lies in its transparent management of carbon reduction projects and resources that reflect global regulations and standards, from organizing project information to keeping records of carbon reduction credits. Companies can also buy and sell credits on Centero’s intermediary carbon credit marketplace.Voluntary carbon reduction projects span a vast range of industries, from manufacturing and chemicals to information technology (IT) and construction. Current ongoing projects include carbon capture and waste management initiatives.Notably, Centero manages all credit information and transactions using blockchain technology. It makes all relevant information accessible to companies — including information about certifiers, verification, and quantity of issued credits — thereby increasing security and transparency in transactions. Credit-related events, such as the transfer of ownership, are also managed through blockchain processes.Through its most recent achievement, Centero has demonstrated a total carbon reduction effect of 186,595 tonnes.“The mandatory market has limited corporate participation, resulting in insufficient trading volume and difficulties in handling the demand for carbon emission rights due to the strengthening of global GHG emission regulations. Through Centero, we will encourage participation from local companies and organizations in voluntary carbon reduction projects and help accelerate a privately-led voluntary carbon market,” said Bang Soo-in, Head of SK C&C’s Digital ESG Group.

news
Web3 & Enterprise·

Apr 11, 2023

NH Bank Establishes Consortium to Build Security Token Ecosystem

NH Bank announced today that Korean banks and fractional investing companies have teamed up to establish a consortium with the aim of building an ecosystem for security tokens. Consortium between banks and fractional investorsThe consortium comprises NH Bank, Suhyup Bank, and Jeonbuk Bank as well as six fractional investing companies, including Seoul Auction Blue, Tessa, and Galaxia Moneytree.The banking sector will contribute to the security token industry by building infrastructure for distributed ledger technology, conducting research on promoting security tokens, and bolstering investor protection. Korean banks’ crypto initiativesNH Bank has been in partnership with domestic Korean crypto exchanges Bithumb and Korbit to provide them with real-name registered bank accounts, demonstrating continued interest in crypto services. Under current law, crypto exchanges in Korea are obliged to hold real-name bank accounts if they want to provide Korean won trading services.This move led by NH Bank shows that traditional banks, which have been more conservative compared to securities companies, are actively striving to secure a position in the security token market.

news
Policy & Regulation·

May 24, 2024

Gate.HK ceases operations and withdraws license application in Hong Kong

Gate.HK, cryptocurrency exchange Gate.io’s Hong Kong entity, is discontinuing its operations and has retracted its application for a crypto trading platform license with the local regulator. The company announced on Wednesday a planned "major overhaul" of its platform and has ceased new user registrations and deposits immediately. In compliance with local regulations, Gate.HK will delist all tokens—including major ones like Bitcoin, Ether and USDT—on May 28, urging users to withdraw their assets by August 28. The trading platform, which launched officially in May 2023, aims to re-enter the Hong Kong market in the future after securing the necessary approvals and contributing to the virtual asset ecosystem.Photo by Kelly Sikkema on UnsplashRegulatory environment and industry responseThe withdrawal of the license application, initially submitted in February 2023, was noted on the website of the Hong Kong Securities and Futures Commission (SFC) on May 22, without a disclosed reason for the withdrawal. The SFC mandates that crypto trading platforms without a submitted license application by Feb. 29 must shut down by May 31 or within three months upon receiving further notice. This regulation has impacted several platforms, including HKVAEX and Huobi HK, both of which have recently withdrawn their license applications and ceased operations or faced operational uncertainties in the region. Currently, the SFC is reviewing applications from 20 crypto firms, indicating significant interest among global exchanges in securing retail trading licenses in Hong Kong. 

news
Loading