Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Jul 28, 2023

Mobile Strategy Game ‘EF Defense’ to Launch on Immutable zkEVM

Mobile Strategy Game ‘EF Defense’ to Launch on Immutable zkEVMWeracle, the Singapore-based developer behind the popular mobile game Endless Frontier, is gearing up to deploy its latest creation, EF Defense, on the Ethereum scaling network, Immutable zkEVM.The tower defense strategy game, currently available on iOS and Android, will receive a significant boost with this move, opening up new opportunities for players and integrating blockchain technology into its gameplay.Photo by Catherine Kay Greenup on UnsplashPlay-to-earn gameEF Defense, a play-to-earn game with stunning visual aesthetics similar to Endless Frontier, transports players to the Land of Abundance, where they must fend off a dark and menacing force threatening the continent of Akaros. Armed with 70 diverse heroes and an array of customization options, players will embark on an epic quest to protect their territory and claim rewards for their strategic prowess.Immutable, a prominent Web3 games publisher headquartered in Australia, is partnering with Weracle to facilitate this transition. The move to the Ethereum scaling network brings the potential for even greater in-game experiences, enhanced security, and unique ownership opportunities through non-fungible tokens (NFTs). While EF Defense already offers hero characters as NFTs on the Ethereum scaling network Polygon, the specific utilization of NFTs and tokens on Immutable zkEVM remains undisclosed.The gaming industry veterans behind MagmaByte have also caught the NFT wave with their upcoming release, Galaxy Commanders. This player-versus-player (PvP) space shooter, developed by former talents from major gaming companies like Electronic Arts (EA), NCSoft, and Nexon, will utilize the Immutable zkEVM network for its launch. Players can expect action-packed space battles and cooperative planetary conquests, utilizing various strategies to claim victory.Based on PolygonImmutable zkEVM is based on Polygon’s zkEVM technology, a layer-2 Ethereum scaling network specially designed for gaming. This integration promises faster and more cost-effective transactions compared to the Ethereum mainnet, ensuring a seamless and enjoyable gaming experience. To cater to gamers new to Web3, Immutable is also working on developing the Passport, a user-friendly wallet to facilitate easy interactions with blockchain-based games.Weracle’s involvement with blockchain gaming through EF Defense is likely to be just a starting point. The studio has ambitious plans to launch more crypto games in the future, cementing its position in the evolving landscape of blockchain-based gaming. Additionally, a digital Weracle Wallet is in the works, intending to create a holistic ecosystem for players and collectors alike.Andrew Sorokovsky, VP Of Global Business Development at Immutable, expressed enthusiasm for Weracle’s transition into Web3 gaming, acknowledging the team’s expertise in the traditional gaming space and predicting significant strides in the realm of blockchain-based entertainment.As EF Defense prepares to enter the world of Immutable zkEVM, players can look forward to an enhanced gaming experience with the added benefits of blockchain technology.The integration of NFTs and the prospect of play-to-earn mechanics has the potential to make a far bigger impact, provided the correct balance is struck between engaging gameplay and the play-to-earn model dynamic.

news
Policy & Regulation·

Aug 18, 2023

Dispute Embroils Bitget in Legal Battle With Crypto Influencer

Dispute Embroils Bitget in Legal Battle With Crypto InfluencerBitget, the crypto exchange registered in Seychelles, finds itself entangled in a legal dispute with prominent crypto influencer Evan Luthra.Photo by Tingey Injury Law Firm on UnsplashAccount freezing allegationsThe conflict stems from Luthra’s allegations of account freezing and loss of funds after a token listing incident in March. Luthra has filed a lawsuit against Bitget, accusing the exchange of withholding $200,000 in Tether (USDT) without adequate explanation, while also freezing his account.The legal drama follows Luthra’s involvement with the Reel Star project, where he served as an advisor for the platform which is aimed at creators. As compensation for his collaboration with the project, Luthra received Reel Token (REELT), the project’s utility token.Bitget alleged market manipulationUpon the listing of REELT tokens, Luthra reportedly sold 1.3 million tokens on Bitget. In response, Bitget claims it faced a manipulative attack orchestrated by a group of traders attempting to profit from market manipulation immediately after the token’s listing. This allegedly caused a significant drop in the token’s price, prompting Bitget’s decision to freeze Luthra’s account.Bitget states that it contacted Luthra seeking an explanation for the suspicious trading behavior. Luthra acknowledged the token sale but failed to provide satisfactory reasons for his actions, according to Bitget’s version of events. The exchange maintains that user protection is its foremost priority and that it takes swift action against illegal or fraudulent behaviors.$16 million damages claimLuthra refutes the allegations, asserting his innocence and citing alleged approval from Reel Star’s Co-Founder Navdeep Sharma for his token sale plans. He seeks a substantial $16 million in damages, in addition to the frozen funds. Luthra claims that Bitget unjustly deprived him of his tokens, asserting his status as a fully KYCed user entitled to access his holdings.In the aftermath of the incident, Bitget conducted an investigation and offered a compensation plan for affected clients. Gracy Chen, Bitget’s Managing Director, emphasized the exchange’s commitment to user protection and its actions against illicit activities on its platform. Addressing the matter on Twitter, Chen didn’t hold back in her commentary on Luthra, stating that he “has a history of fraudulent activities,” which she says were exposed by crypto journalist CoffeeZilla.The legal dispute has ignited debates within the crypto community. Supporters of Luthra contend that his case underscores broader issues faced by users of centralized exchanges, shedding light on the need for improved user rights and protection. On the other hand, some argue that Bitget acted appropriately to safeguard its users and the market integrity.CZ brought into the disputeThe legal battle has attracted attention from influential figures in the crypto industry. Against a backdrop of a very public airing of the dispute on Twitter, in a recent tweet Luthra invited Changpeng Zhao (CZ), the CEO of Binance, to respond to Luthra’s claim that Bitget spreads rumors about other exchanges. CZ was having none of it, writing: “You should talk to them, right? We are not a regulator for other exchanges.”The case highlights the intricate challenges surrounding market manipulation and token listings within the crypto space. As it unfolds, the outcome could potentially set a precedent for similar situations involving token listings, market manipulation, and user protection.

news
Policy & Regulation·

Jan 20, 2024

China establishes metaverse working group with Chinese tech giants

China's Ministry of Industry and Information Technology (MIIT) has stepped into the realm of the metaverse by forming a working group tasked with setting standards for the burgeoning technology.Photo by Li Yang on UnsplashChinese corporate participationThe announcement, made on Friday, revealed that the working group would comprise representatives from the government, academic institutions and major corporations. In its statement, MIIT explained that the establishment of the metaverse working group aligns with the nation's emphasis on industrial development within the technology sector. Notably, the group will feature key figures from major Chinese tech corporations, including Huawei, Ant Group, ZET, Tencent, Baidu, NetEase, Sense Time and others. Public feedback on the selection of group members is invited until Feb. 18, although the specific areas of focus for the group are not detailed in the document. Initial in-roadsThe working group’s headline tech participants have all made some initial in-roads into metaverse technology. Baidu established its own metaverse project, XiRang, in 2021. Late last year it partnered with Qualcomm on the use of extended reality (XR) technology for use on a new metaverse platform. Huawei is paying attention to the promising metaverse space by building up a catalog of metaverse-related patents. Like Baidu, Tencent is focusing on developing XR technology with metaverse development in mind. Last year NetEase collaborated with a Chinese liquor brand to launch a winery-themed metaverse, while issuing NFTs linked to liquor bottles. Establishing metaverse standardsChina has been contemplating the formulation of metaverse standards for some time. In September 2023, MIIT advocated for the creation of a dedicated working group to address the ongoing challenges in metaverse technology. The government's overarching objective is to ensure the healthy and orderly development of the metaverse industry through standardization and guidance, reducing redundant investment costs and fostering collaborative forces for industrial development. Analysts from JPMorgan foresee a potential uptick in the value of Chinese tech stocks if the metaverse gains traction in the country. According to their analysis, Chinese web giants like Tencent and NetEase stand to benefit significantly from metaverse development. Even non-web companies such as China Mobile, Sony and Agora could witness positive impacts should the technology gain widespread adoption. In fact, China Mobile led the development of a metaverse industry alliance in China in 2023. Regional developmentIn a December document, MIIT outlined plans to formulate strategy documents clarifying the development path of Web3.Last year, several local governments in China committed to the development of the metaverse industry. Sichuan, a province once known as a crypto mining hub, aims to reach a market size of 250 billion yuan ($35.1 billion) in the metaverse industry by 2025. Last May, the city of Zhengzhou announced policy proposals to support metaverse companies. The same month, the province of Henan established a $21.7 million fund to support metaverse-related projects. The following month, an initiative was established in Nanjing to nurture metaverse development. Additionally, Shandong province has plans to grow its metaverse-related initiatives to achieve a market size of 150 billion yuan by 2025. 

news
Loading