Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Oct 03, 2023

SBI Holdings and TradeFinex Partner to Create a Trade Finance JV in Japan

SBI Holdings and TradeFinex Partner to Create a Trade Finance JV in JapanJapanese financial services conglomerate SBI Holdings has joined forces with UAE-based TradeFinex to establish a dynamic joint venture. The objective of the partnership is to propel the widespread adoption of the XDC Network within Japan’s trade finance sector.Details of the agreement between the firms emerged last Friday. The strategic collaboration represents a move toward harnessing blockchain technology to infuse transparency, efficiency, and accessibility into the fabric of trade finance and supply chain management.At its core, the XDC Network stands as an enterprise blockchain platform which is compatible with the Ethereum virtual machine (EVM). In recent times, the XDC Network has cultivated partnerships with several international organizations, including the World Trade Organization (WTO) and the International Chamber of Commerce (ICC). It has pioneered solutions aimed at cost reduction, transaction acceleration, and transparency augmentation within the trade finance sphere.Photo by Timelab on UnsplashBuilding upon related partnershipSBI Holdings, deeply ingrained in Japan’s financial services sector, has taken significant strides to embrace the potential of blockchain technology. Earlier this year, its subsidiary, SBI VC Trade, partnered with the XDC Network, becoming the inaugural Japanese exchange to facilitate the cryptocurrency asset XDC. Building upon this previous collaboration, SBI VC Trade has been proactive in championing the expansion of the XDC Network’s presence in Japan.The freshly minted joint venture between SBI Holdings and TradeFinex has the potential to serve as a catalyst for further XDC Network growth in Japan. A central goal is to localize XDC Network-related information, thereby rendering it more accessible to Japanese businesses and investors.Additionally, the venture is actively scouting for cryptocurrency exchanges who are prepared to use and promote the XDC network, further amplifying its adoption. Exploring collaborations with subnet and layer-2 enterprises forms an integral part of their strategy.Japan’s evolving stance on blockchainThe timing of this collaboration coincides with Japan’s evolving stance on blockchain technology and cryptocurrencies. Emerging reports indicate the Japanese government’s contemplation of allowing startups to raise capital through cryptocurrency tokens, marking a seismic shift away from conventional stock listing processes.In April the Japanese government released a whitepaper on Web3, in its efforts to explore ways to foster innovation in the emerging sector. Furthermore, Japan’s National Tax Agency has made adjustments to its cryptocurrency-related tax code, underscoring a proactive stance toward regulating the cryptocurrency industry. Related to that, the country’s Financial Services Agency (FSA) has been exploring tax exemptions relative to unrealized crypto gains.Japan has become known historically as a center of technological innovation. There have been soundings recently that it can rediscover its abilities in that respect through the development of Web3.The strategic alliance between SBI Holdings and TradeFinex charts a promising trajectory for the XDC Network within Japan’s trade finance sector. Anchored in a project that aspires to offer innovation, transparency, and operational efficiency, this joint venture offers considerable potential to spearhead the adoption of blockchain technology within one of the world’s most prominent financial markets.

news
Policy & Regulation·

Nov 25, 2025

Regulators clamp down on crypto energy as nations shift priorities

The blockchain network underpinning Bitcoin, the world’s largest cryptocurrency, requires an energy volume comparable to the annual consumption of Thailand. According to Digiconomist’s Bitcoin Energy Consumption Index, the protocol utilized roughly 204.44 terawatt-hours (TWh) of electricity between Nov. 18, 2024, and Nov. 18, 2025.Photo by Fré Sonneveld on UnsplashFiscal losses drive Malaysian oversightAmid these intense energy demands, Malaysia’s primary electricity utility has recorded substantial financial impairments attributed to illicit activities. Tenaga Nasional Bhd (TNB) reported losses totaling 4.57 billion ringgit ($1.1 billion) from illegal crypto-mining operations over a five-year span. In a Nov. 19 report by The Edge Malaysia, the Ministry of Energy Transition and Water Transformation (Petra) disclosed these figures to parliament, specifying that the unauthorized mining occurred at 13,827 locations between 2020 and August of this year. To counter these infractions through regulatory channels, Petra has formed a special committee scheduled to convene before year-end. This body aims to recommend enhancements to the Electricity Supply Act, which currently delineates penalties based on the offender's classification. Domestic violators face fines ranging from 1,000 to 50,000 ringgit ($240 to $12,000), imprisonment of up to one year, or both. Penalties escalate for non-domestic entities, involving fines between 20,000 and one million ringgit ($480 to $240,000) and potential prison terms of up to five years. Despite these provisions regarding electricity theft, a specific legal code regulating the act of crypto mining remains absent, creating a jurisdictional void. International bans and grid reallocationStrategies to curtail electricity usage by crypto miners are becoming evident elsewhere in Southeast Asia as well. Laotian Deputy Energy Minister Chanthaboun Soukaloun told Reuters last month that the nation intends to suspend electricity supplies to crypto miners by early 2026. He cited the sector's minimal economic contribution and low job creation as primary factors. Consequently, the state plans to redirect power to high-priority sectors, including AI data centers, metals processing, and electric-vehicle manufacturing. Parallel restrictions are emerging globally. In October, the government of British Columbia enacted a permanent prohibition on new BC Hydro connections for crypto miners to safeguard the Canadian province’s energy reserves. Officials pointed to the industry’s "disproportionate energy consumption and limited economic benefit" as the rationale for the policy. The debate over thermal innovationConversely, some enterprises are exploring methods to capture thermal output from Bitcoin mining to heat residential and commercial properties. If viable, such repurposing could utilize the considerable thermal byproducts of mining. A K33 Research study cited by CNBC indicates the industry generates roughly 100 TWh of heat annually, a figure sufficient to warm the entirety of Finland. However, industry consensus on the feasibility of these applications remains elusive. Proponents suggest that mining infrastructure could be situated in proximity to heat consumers. Skeptics, however, contend that the reliance on application-specific integrated circuit (ASIC) chips makes this impractical, arguing that the technical difficulty of mining a block renders household participation unfeasible. Despite these differing views, the concept continues to attract attention as a potential avenue for innovation in energy distribution. As jurisdictions like Malaysia and British Columbia tighten regulatory oversight, the cryptocurrency sector faces mounting pressure to address its energy footprint. The divergence between government restrictions and industry-led efficiency proposals underscores the complex relationship between digital asset infrastructure and global energy resources. Given the shifting landscape of policy and technology, the outlook for sustainable large-scale crypto mining remains uncertain, as governments weigh energy demands against economic benefits and the industry searches for more efficient ways to operate.

news
Policy & Regulation·

Oct 23, 2023

Dunamu’s Legal Team Recognized by Korean Police for Cyber Security Contributions

Dunamu’s Legal Team Recognized by Korean Police for Cyber Security ContributionsDunamu, the blockchain and fintech company behind South Korea’s largest cryptocurrency exchange Upbit, recently announced a noteworthy security achievement. At the 16th Cyber Security Awards organized by the Korean National Police Agency (KNPA), the leader of Dunamu’s Legal Team 3 was recognized with the KNPA Commissioner General’s Certificate of Appreciation. This accolade was in acknowledgment of the legal officer’s pivotal role in fostering collaboration between the private sector and police to combat the rising tide of cryptocurrency-linked crimes.Photo by Franck on UnsplashSupport guides and educational resourcesDunamu stands out as the only Korean virtual asset service provider (VASP) to have an employee distinguished in this manner this year. It’s worth noting that Dunamu’s legal teams have been proactively cooperating with law enforcement, providing them with investigation support guides and educational resources.A representative from Dunamu’s legal teams expressed gratitude to all team members for their collaborative efforts in combating virtual asset-related crimes and appreciated the recognition for their achievement. The official further emphasized Dunamu’s ongoing dedication to maintaining close cooperation with police and investigative bodies, aiming to cultivate a healthy virtual asset ecosystem.Awards since 2008The Cyber Security Awards were established in 2008 to recognize and honor those making significant contributions to cyberspace security. The awards not only motivate cyber police officers but also aim to bolster collaboration between the police and the private sector.This year, 27 distinguished individuals — including police officers, civil servants, and ordinary citizens — were recognized at the ceremony held on October 19 in Songdo Convensia, Incheon. They received commendations and certificates of appreciation for their contributions in areas ranging from cybercrime investigation and prevention to digital forensics.

news
Loading