Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Jun 07, 2023

SAND Token to be Listed on Japanese Crypto Exchange bitFlyer

SAND Token to be Listed on Japanese Crypto Exchange bitFlyerJapanese crypto exchange bitFlyer has recently announced its plans to list The Sandbox (SAND) on its trading platform, making it the 22nd crypto asset to be available on bitFlyer. Specific details are yet to be announced. This move reflects bitFlyer’s commitment to expanding its offering and providing customers with more investment options and opportunities in the realm of Web3.Photo by Shubham Dhage on UnsplashGlobal presenceFounded in 2014 with a mission to simplify the world through blockchain technology, bitFlyer has taken its crypto asset trading business to the global stage. Its expansion includes sister companies bitFlyer USA and bitFlyer Europe, which have allowed the exchange to extend its reach beyond Japan.Blockchain-powered metaverseThe Sandbox is a metaverse platform that harnesses the power of blockchain technology, empowering users to create and possess digital content using the platform’s tools. Moreover, The Sandbox features virtual land called LAND, which is regularly utilized by companies for hosting events and various other activities. At the heart of this ecosystem lies the SAND token, which enables users to trade user-generated content, participate in governance by voting, and engage in staking.Attention in East AsiaNotably, The Sandbox has been generating significant attention in East Asia. Last month, the metaverse platform initiated an event titled “Hallyu Rising,” collaborating with renowned Korean brand partners, including automaker Renault Korea. As part of this event, Renault Korea launched the Renault Korea Hub within The Sandbox’s environment. This hub gives car enthusiasts a unique chance to design their own vehicles and enjoy exclusive experiences. The event also included a land sale, offering users the chance to acquire LAND adjacent to the Korean brands, thereby encouraging more active user engagement.

news
Web3 & Enterprise·

Aug 12, 2023

Boyaa Interactive Greenlights $5 Million Investment in Bitcoin and Ether

Boyaa Interactive Greenlights $5 Million Investment in Bitcoin and EtherBoyaa Interactive International Limited, a Hong Kong-based investment holding company with a track record in developing online chess, card, and puzzle games, has made a strategic move with a proposed investment in digital assets.The company’s board of directors has recently given the green light for the allocation of a substantial budget amounting to $5 million for the purpose of acquiring cryptocurrencies.Photo by Traxer on UnsplashWeb3 positioningThe Chinese company, incorporated in the Cayman Islands, announced the move as Boyaa Interactive seeks to position itself for a dynamic shift into the realm of Web3.While the exact allocation breakdown was not detailed in the disclosure, the company outlined that its primary focus would be on procuring established cryptocurrencies, specifically Bitcoin (BTC) and Ether (ETH). Boyaa Interactive intends to execute these purchases through regulated and licensed trading platforms within the upcoming year.In a letter addressed to its shareholders and potential investors, the company emphasized the strategic nature of this decision:“The purchases of cryptocurrencies are for the consideration of the Group’s future business layout into the field of Web3. The Board is of the view that the purchases of cryptocurrencies (including mainly Bitcoin (BTC) and Ether (ETH)) by the Group are in the interests of the Company and its shareholders as a whole.”A challenging recent historyThe move towards cryptocurrencies is a significant pivot for Boyaa Interactive, a company that has navigated a series of challenges in recent years. In 2018, the company’s Chairman and CEO, Zhang Wei, faced legal troubles and was sentenced to 12 months in prison for bribery, which led to his resignation from all executive and management positions.Subsequent restructuring saw Dai Zhikang stepping in as the new Chairman of the board, while Tao Ying assumed the role of an Executive Director and Chairman of the Nomination Committee.Financially, Boyaa Interactive experienced a tough period marked by revenue contraction. The company reported revenue declines over the course of 2018, largely attributed to a governmental crackdown on online poker applications and the discontinuation of poker as a recognized competitive sport. Regulatory risks stemming from the Chinese government’s stance on Texas Hold’em poker games resulted in a substantial falloff in revenue by comparison with past performance.Funds seizureThese challenges cascaded into the following year, when the company encountered a substantial freeze on its funds. In 2019, a Chinese court ordered the freezing of RMB 635 million (approximately $88.6 million) belonging to Boyaa Interactive, following the legal actions against Zhang Wei and his associated entities.One of the company’s subsidiaries, Boyaa Shenzhen, was found guilty of offering bribes. The company responded by clarifying that the frozen funds could potentially be confiscated if linked to Zhang’s misconduct. However, Boyaa Interactive also stressed that it had not been directly implicated in the case, thus mitigating the legal risks to the broader organization.Amidst these adversities, Boyaa Interactive’s decision to invest in cryptocurrencies demonstrates its openness to adapting to changing technological landscapes and exploring new opportunities in Web3.

news
Policy & Regulation·

May 10, 2023

Hong Kong Says No to Light Touch Regulation

Hong Kong Says No to Light Touch RegulationThe CEO of the Hong Kong Monetary Authority (HKMA) has said that while the autonomous territory will allow innovation to develop in the crypto space, that will not mean light touch regulation.Photo by Ruslan Bardash on UnsplashLowering guard railsAfter a three year hiatus, the Bloomberg Wealth Asia Summit returned to Hong Kong on Tuesday. Speaking at the conference, Eddie Yue, the CEO of the HKMA, Hong Kong’s regulatory body, outlined that the territory intends to enable innovation relative to crypto businesses that establish themselves in Hong Kong.“We will let the industry develop and innovate, we will let them create an ecosystem here,” he said. However, he added the following caveat: “But that doesn’t mean light touch regulation. If any participant thinks that the regulation is too tight, they’re welcome to go elsewhere.”Yue outlined that over the course of the past three years, guardrails relative to the operation of crypto-related activities were excessively high. Yue alluded to a new approach that sees those guard rails dropped to a level whereby innovation will be enabled in the digital assets space. However, he followed up by underlining the fact that the Authority has no intention of following a light touch regulatory approach.No safeguards not an optionAlthough acknowledging that Hong Kong may have been excessively crypto unfriendly relative to digital asset regulation in the recent past, he believes that Hong Kong has now got it right. “Our guardrails are lower, to a reasonable and sustainable level,” Yue said.The HKMA regulator flagged jurisdictions that provide little or no guardrails at all as the ones that will run into difficulties. “If you look elsewhere, there are no guardrails in some places, the guardrails are very low and there you see problems”, Yue clarified.He cited FTX as a stand out example of a basic lack of internal controls. FTX International was based in the Bahamas. While customers of FTX International find themselves in a difficult position, those of subsidiary companies FTX Japan and FTX Europe are having their funds returned as a direct consequence of much better regulatory safeguards in those regions.“All those wrongdoings by the platforms that we saw in the last one or two years will not happen in Hong Kong,” Yue claimed.A continuing trendWhile many commentators and critics from the conventional world have described bitcoin and crypto as a ponzi or a passing fad, Yue pointed out that digital assets are not going anywhere and that the trend towards digital assets will continue. Expanding further, he articulated that the overarching digital assets sector encompasses much more than just crypto: “Virtual assets or crypto is actually a very broad term. It’s not really about crypto, you’re talking about stablecoins or tokenized assets in the future.”A mere $0.3 trillion of illiquid real world assets have been tokenized thus far. It’s anticipated that this level of tokenization will climb to $16 trillion by 2030.

news
Loading