Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Jun 26, 2023

Wemade Unveils Blockchain-Powered Platform for Various Communities

Wemade Unveils Blockchain-Powered Platform for Various CommunitiesSouth Korean gaming company Wemade today unveiled their latest creation, Wepublic, a blockchain-powered platform for various communities. The objective of Wepublic is to establish a transparent and trustworthy digital society on the WEMIX3.0 Mainnet.Photo by Pixabay on PexelsFrom political parties to NGOsInitially built as a fundraising platform, Wepublic caters to entities of any scale or domain, be it political parties, religious groups, or non-profit organizations. Wepublic is committed to transforming itself into a platform for everyone.By leveraging blockchain, Wepublic ensures that all information and records stored on the platform are transparent, making them immune to counterfeiting and diversion. Furthermore, Wepublic is dedicated to fostering inclusivity and democratic decision-making. Every member within a group on Wepublic has the ability to engage in organizational activities and contribute to fair decision-making processes.Four proof protocolsIn the near future, Wepublic will introduce the “Wepublic Wallet,” enabling users to create or participate in decentralized autonomous organizations (DAOs). To ensure transparency and reliability of DAO operations, Wepublic relies on four proof protocols. These protocols serve to verify user identities, credentials, account balances, and the outcomes of governance processes.The first protocol utilizes decentralized identifiers (DIDs) to safeguard personal information, prioritizing user privacy and security. The second protocol employs soulbound tokens (SBTs) to effectively manage groups within the platform. The third protocol provides visibility into account balances and transaction records, adding an additional layer of transparency. Lastly, the fourth protocol ensures the transparent recording of all governance processes on the blockchain, promoting accountability and trust.

news
Policy & Regulation·

Jan 06, 2026

Japan eyes ‘year of digital’ as finance minister signals crypto shift

Japan and China are moving in different directions on digital finance. In Japan, senior officials are signaling a push to bring cryptocurrencies further into the mainstream financial system. In China, regulators are doubling down on limits for private-sector tokenization even as the central bank expands a state-led digital currency model.Photo by Nat on UnsplashTraditional exchanges to anchor crypto pushSpeaking at the Tokyo Stock Exchange on Jan. 5, Japanese Finance Minister Satsuki Katayama framed 2026 as “the inaugural year of digital” in her New Year’s address, according to local outlet CoinPost. She said she expects cryptocurrency adoption to broaden as commodity and stock exchanges take on a larger role, arguing that established market infrastructure will be key to realizing the benefits of blockchain-based assets. Pointing to the U.S., she noted that exchange-traded funds are commonly used as an inflation hedge, and suggested Japan could move in a similar direction. Katayama also struck an upbeat tone on the wider economy, saying she expects Japanese stocks to hit new record highs this year. She cast 2026 as a potential turning point as Japan seeks to move beyond a long stretch of deflation, and called for responsible but proactive fiscal policy alongside targeted investment in growth sectors. Her comments come as Tokyo considers a major overhaul of how crypto gains are taxed. Under a government proposal, profits from cryptocurrencies would be taxed at a flat 20%, aligning them more closely with levies on stocks and foreign-exchange trading. The framework would also cover crypto-linked ETFs and derivatives. Currently, crypto gains are treated as miscellaneous income, leaving investors subject to progressive rates that can climb to roughly 55% once local taxes are included. The proposed reforms would bring crypto assets under the Financial Instruments and Exchange Act. While the package is slated for discussion during the upcoming ordinary Diet session, which is scheduled to begin on Jan. 23, officials do not expect it to take effect before 2028, given the scope of the required legal and regulatory changes. Industry groups flag RWA tokenization risksChina, by contrast, continues to take a restrictive stance toward private digital-asset activity. Seven major financial industry associations—including the National Internet Finance Association of China, the Banking Association, and the Securities Association—issued a joint statement warning that the tokenization of real-world assets (RWAs) is illegal and amounts to a “risky business model,” according to Wu Blockchain, citing a WeChat post published last month. The associations argued that RWA tokenization still functions as a form of unauthorized fundraising barred under existing securities laws. They also warned of risks tied to both the projects and their underlying assets, including fraud, operational failures, and speculative hype, adding that even when the assets themselves are legitimate, token structures remain unreliable and could pose spillover risks to other parts of the financial system. The statement added that such activities have not received regulatory approval. The warning fits with Beijing’s broader, state-led approach to digital finance. Last month, Lu Lei, a deputy governor of the People’s Bank of China (PBOC), warned that unchecked private-sector innovation could pose challenges for monetary policy, arguing that the rapid growth of digital assets and stablecoins risks weakening central banks’ control over money flows. Against that backdrop, Lu said the PBOC has rolled out a new operational framework for its central bank digital currency that took effect on Jan. 1. The move places the digital yuan in a deposit-like role within the commercial banking system under a two-tier structure, with the central bank overseeing rules and infrastructure and commercial banks handling wallets, payments, and compliance. By late November 2025, the digital yuan network had processed 3.48 billion transactions totaling 16.7 trillion yuan ($2.3 trillion), underscoring how China is channeling digital finance through a centrally controlled system. The system includes about 230 million personal wallets and 18.84 million corporate wallets. 

news
Web3 & Enterprise·

Dec 13, 2023

Bitget invests in Morph layer 2 network

Bitget invests in Morph layer 2 networkBitget, the Seychelles-incorporated crypto derivatives exchange, has injected a multi-million dollar investment into Morph, a Layer 2 blockchain that puts consumer experience at the forefront.Photo by Shubham Dhage on UnsplashCombining zero knowledge and optimistic rollupsThe collaboration, unveiled on Monday, signals a significant stride toward cultivating a novel, value-driven decentralized application (dApp) ecosystem. Morph, formerly known as Morphism, has garnered attention for its unique use of roll-up technology. By seamlessly blending optimistic and zero-knowledge (ZK) roll-ups, Morph aims to revolutionize scalability, reduce cost barriers, expedite dispute resolutions and ensure secure and adaptable transactions.The project’s modular framework allows individual components of the ecosystem to evolve independently, staying abreast of rapid innovations in consumer applications.Combating MEVA distinctive feature of Morph’s design is the Decentralized Sequencer Network, a mechanism that ensures swift and cost-effective Layer 2 transactions. This challenges the dominance of maximal extractable value (MEV) and eradicates central points of control. MEV involves the maximum amount of value that can be extracted from a block on a blockchain network. It may be manipulated through the ordering and sequencing of transactions on the chain.Technological innovation is not the sole objective of the Morph development team. Their ambition extends to creating a space where dApps seamlessly integrate into users’ daily lives, delivering tangible value. This consumer-centric approach prioritizes user experience through easy onboarding processes and intuitive interfaces. The network is attractive to developers due to lower cost barriers and accelerated dispute resolution.Gracy Chen, Managing Director of Bitget, underscored the significance of the collaboration, praising Morph’s exceptional team, multicultural approach and strategic capabilities. Chen notes that Morph’s emphasis on a decentralized and consumer-centric approach aligns seamlessly with Bitget’s vision. This partnership, she believes, has the potential to transform the blockchain space, making the technology more accessible for everyday use and unlocking widespread consumer adoption.Cecilia Hsueh, Co-Founder and CEO of Morph, expressed gratitude for Bitget’s support, emphasizing that the recent capital infusion underscores confidence in Morph’s unique value proposition, setting the stage for an upcoming seed funding round. The strategic alliance with Bitget provides Morph with a robust platform for growth, tapping into Bitget’s expansive user base of 20 million exchange users and 12 million Bitget Wallet users. Notably, Morph had previously entered into a strategic alliance with Foresight Ventures, a crypto fund based in Singapore.Looking ahead, Morph is gearing up for significant milestones as it develops further. The project plans to intensify the refinement of its technical framework and broader ecosystem in the coming months. Notably, Morph is slated to launch its public testnet in January 2024, followed by the beta mainnet of its Optimistic zkEVM, which is scheduled for Q2 2024.As Bitget continues to forge ties with up-and-coming Web3 entities, this collaboration with Morph has the potential to propel the project towards its strategic goals but also sets the stage for a transformative shift in the landscape of Layer 2 solutions.

news
Loading