Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Policy & Regulation·

Jun 01, 2023

Korean Crypto Exchange Alliance Reveals Standardized Regulation Guidelines

Korean Crypto Exchange Alliance Reveals Standardized Regulation GuidelinesThe Digital Asset eXchagne Alliance (DAXA), consisting of five leading cryptocurrency exchanges in South Korea, today revealed standardized regulation guidelines, according to a report by news media The Asia Business Daily.Photo by Nick Fewings on UnsplashStandardized guidelinesTwo important documents — the standardized internal control framework and the code of conduct and ethics — were released by DAXA today. These documents were developed based on data provided by financial investment firms and member exchanges. Reviewed by DAXA members and advisors, this documentation represents a significant milestone as it is the first of its kind to address the unique characteristics of the crypto industry. The establishment of unified rules and regulations through the collaborative efforts of the member exchanges stands as a commendable achievement.Internal control frameworkThe internal control framework consists of five parts, encompassing a total of 68 articles. These parts cover general provisions; governance of virtual asset service providers (VASPs); organization and standards for internal control; compliance officers and internal control system management; and compliance details.Code of ethicsThe code of conduct and ethics comprises five chapters with 24 articles. These chapters focus on general provisions, customer ethics, employee ethics, corporate management ethics, and societal ethics.DAXA Vice Chairman Kim Jae-jin expressed optimism that these guidelines will serve as a valuable reference for all VASPs, fostering the development of a fair, trustworthy, and globally competitive crypto market.DAXA’s websiteLast month marked the launch of DAXA’s official website, and their YouTube channel has been active since January. The alliance is made up of five member exchanges: Gopax, Bithumb, Upbit, Korbit, and Coinone. At the helm of the alliance is Chairman Lee Sirgoo, who concurrently serves as CEO of Dunamu — the company operating Upbit, the largest cryptocurrency exchange in the nation.

news
Policy & Regulation·

Sep 12, 2025

China funds research on stablecoin risks to financial system

China’s leading science foundation has initiated a research program to examine the effects of stablecoins, reflecting concerns that such digital currencies could pose a risk to the nation’s financial system and its fiat currency. According to the South China Morning Post, the National Natural Science Foundation of China (NSFC) is now offering grants for studies focused on stablecoins and the creation of cross-border monitoring frameworks. The foundation expressed that the unmonitored circulation of private stablecoins, particularly those pegged to the U.S. dollar, could weaken capital controls and present a potential challenge to the yuan. This initiative emerges as governments around the world, from the U.S. to regional financial centers, are actively developing rules for the digital asset sector.Photo by  Christian Lue on UnsplashStrategic research and internal debateThe NSFC will fund the projects with grants valued between 200,000 and 300,000 yuan ($28,042 to $42,063). Researchers are expected to complete their work within a year and deliver policy recommendations on how China can manage the challenges posed by global stablecoins and contribute to digital finance governance. The deadline for applications is Oct. 9. This research program is set against a backdrop of internal discussion in China regarding the possible launch of a yuan-backed stablecoin. While some economists support the idea of boosting the yuan's international profile, Bloomberg noted that former central bank governor Zhou Xiaochuan has advised caution. He recently said the high efficiency of China's current payment systems and warned that financial stability could be threatened by speculation in the stablecoin market. Analysts believe any state-sanctioned yuan stablecoin would likely be confined to offshore markets and tied to the offshore CNH. Global regulatory landscapeChina’s examination of stablecoins is part of a broader global trend of increased regulatory focus on the asset class. In Hong Kong, a new ordinance took effect on Aug. 1, creating a mandatory licensing system for stablecoin issuers under the oversight of the Hong Kong Monetary Authority. Other Asian nations are also taking action. South Korea’s government is reportedly exploring a model for a won-pegged stablecoin involving a consortium of banks and non-bank entities. Separately, Cointelegraph reported that Kyrgyzstan has introduced legislation outlining a regulatory framework for such assets. Developments are also accelerating in the U.S., where the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act was signed into law, creating a federal structure for stablecoin oversight. On a commercial level, a Minnesota-based credit union, St. Cloud Financial, intends to introduce its own stablecoin later this year, a move highlighted by Cointelegraph. This token, named Cloud Dollar (CLDUSD), is designed to integrate with the credit union's banking system to facilitate faster and cheaper transactions for its members within a regulated environment.

news
Web3 & Enterprise·

Dec 15, 2023

Hitachi collaborates with Concordium on biometric crypto wallet

Hitachi collaborates with Concordium on biometric crypto walletJapan’s Hitachi Solutions, a subsidiary company of the Hitachi multinational conglomerate, has joined forces with the Concordium Foundation, unveiling a collaboration that centers on a state-of-the-art biometric crypto wallet.Photo by Nuno Antunes on UnsplashAlternative approach to securing cryptoAnnounced on Tuesday by the Concordium Foundation, a Swiss-based development team behind the Concordium layer one blockchain, this “proof of technology” initiative has the potential to fundamentally change how users access and secure their cryptocurrency accounts.Breaking away from traditional methods, the proposed biometric crypto wallet leverages users’ fingerprints or facial scans to generate a set of seed words, eliminating the need for users to store or remember them. This novel approach simplifies the restoration process, allowing users to recover their accounts with a mere biometric scan.Improving UXIf crypto and Web3 are to be adopted by ordinary people en-masse, user experience has long been identified within the sector as an area that still requires development. Making users responsible for the storage of a private key is fraught with difficulty, given the likelihood of private keys being lost or compromised.Various approaches are being taken to solve this issue. Tangem Wallet is one such alternative that utilizes near-field communication (NFC) in combination with an app and a card with an inbuilt chip, negating the need for the user to memorize a private key.This biometric-centered approach from Hitachi and Concordium represents another user-friendly approach to the problem of user authentication, harnessing the power of Hitachi’s Public Biometric Infrastructure (PBI) and Concordium’s self-sovereign identity framework. The result is an account creation process based entirely on biometric data, enhancing both security and user convenience.Complementary technologyConcordium’s network, with its stringent ID process for account creation to combat malicious activities, stands to gain substantial benefits from this technology. The biometric wallet will fortify users’ access to their IDs, a critical aspect of network security. Moreover, the technology’s applicability extends beyond Concordium, offering potential integration with any blockchain network.Users of the biometric wallet will have the flexibility to unlock their accounts either by regenerating seed words through a biometric scan or by decrypting a copy of the seed words. This dual-layered approach ensures that access is granted solely through the user’s unique biometric data, enhancing security and mitigating the risk of loss or theft.Developing this cutting-edge technology poses challenges, particularly in handling the inherent “fuzziness” of biometric data, where no two scans produce identical results, even from the same individual. Hitachi’s team addressed this by employing fuzzy key generation and specialized error correction technology, effectively distinguishing between scans.Unlike traditional crypto wallets that necessitate secure storage of seed words, the biometric wallet by Hitachi and Concordium, alongside solutions like multiparty-computation wallets and magic links, aims to overcome this hurdle. The goal is to resolve the issue of lost backup, a significant barrier to wider crypto adoption.This is not Hitachi’s first foray into the crypto/blockchain space. In mid-November the company announced a collaboration with the Japan Exchange Group (JPX), banking giant Nomura and Nomura portfolio company BOOSTRY to launch a $69 million digital green bond on the blockchain. In October Hitachi joined a consortium of Japanese companies with a view towards developing decentralized identity technology.

news
Loading