Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Jun 24, 2025

Nano Labs lines up $500M to fund BNB treasury

Nano Labs, a Web3-focused semiconductor design company listed on the Nasdaq (NA) and headquartered in Hangzhou, China, has arranged $500 million in financing to fund a BNB treasury. In a press release published on the company’s behalf by GlobeNewswire on June 24, Nano Labs outlined that it has entered into a convertible notes purchase agreement with a number of investors. Convertible promissory notes to the value of $500 million will be issued. Holders of the notes, which mature in 360 days, have the option to convert them to Class A ordinary shares at an initial conversion price of $20 per share. Unconverted notes will not accrue interest, but will be repaid in line with the initial principal amount at maturity. 5%-10% of BNB’s total supplyNano Labs asserted that the agreement “marks an important step in the company’s strategic growth.” It stated that as part of the initiative it plans to conduct an in-depth assessment of the BNB token, the native token of the BNB Chain ecosystem. The token enables transactions on the BNB Chain and access to various services and decentralized applications (DApps) that run on the blockchain network. In the initial phase of the initiative, Nano Labs plans to acquire $1 billion worth of BNB through convertible notes and private placements. In the long term, the firm plans to build up a holding equal to 5% to 10% of BNB’s total circulating supply. On X, @Whdysseus, the pseudonymous founder of Asian Web3 and crypto financial media project BroadChain Finance, commented on Nano Labs' BNB reserve initiative, considering it to be a BNB version of the Bitcoin treasury strategy pioneered by American firm Strategy (formerly MicroStrategy).Photo by Vadim Artyukhin on UnsplashShare price surgeChangpeng Zhao (CZ), the co-founder and former CEO of Binance, who has been heavily involved in the development and overall vision of BNB Chain, outlined on X that Nano Labs’ share price “went through the roof” following the announcement. He added that none of his affiliated entities participated in the funding that Nano Labs has put in place. At the time of writing, Nano Labs stock (NA) was trading at $14.85, up 36.36% over the course of 24 hours. Nano Labs isn’t the only corporate entity to declare an interest in holding BNB. According to a report published by Bloomberg on June 23, former executives at Coral Capital, a Japanese venture capital firm, are understood to be in the process of raising $100 million through a newly formed entity called Build & Build Corporation, in order to launch a crypto treasury that will invest in BNB. In another positive development, on-chain analytics firm Nansen highlighted last month that the BNB Chain had seen active addresses double to two million.  Earlier in May, Geoff Kendrick, head of digital asset research at Standard Chartered, outlined in a research report that the BNB token could reach a unit price of $2,775 by 2028. Kendrick maintained that the deflationary nature of the token, together with its ties to the Binance exchange platform, are factors that support its long-term value.

news
Policy & Regulation·

May 16, 2023

China’s Fuzhou City Offers Incentives to Entice Blockchain Start-Ups

China’s Fuzhou City Offers Incentives to Entice Blockchain Start-UpsAdministrators in Fuzhou city, the capital and one of the largest cities in China’s Fujian Province, have introduced a raft of policies aimed at enticing blockchain-centric companies to establish themselves in the city.Photo by 尧智 林 on UnsplashMonetary rewardsThe measures are understood to include rent subsidies applicable to the use of commercial office space in the city, as well as the payment of cash rewards based on such start-up businesses hitting various revenue targets. The cash reward incentives are being capped at 500,000 yuan, around $71,800 US dollars, for each applicable project.The city administrators are also offering cash rewards to institutions within the city area and local blockchain firms in cases where they attain government-issued certifications. Another category through which these entities can reap more cash rewards is in providing training services centered upon blockchain technology.A blockchain firm basing itself within the city limits that is successful in attaining state certification reflecting its status as a national level laboratory specializing in blockchain technologies may be awarded as much as 1 million yuan ($144,000).Rent subsidiesThree specific industrial locations are applicable where the rent subsidy is concerned. Blockchain-based businesses wanting to avail of that incentive will have access to an annual rent subsidy of up to 600,000 yuan ($86,300) for every 1,000 square meters of commercial office space that they rent.Stepping up activityThere seems to be heightened activity related to various aspects of blockchain-related technology within China’s borders in recent months. It appears that while the country is taking the initiative with blockchain-related technology, that excludes the development of or open market use of decentralized cryptocurrencies.China has been pursuing a policy of pushing cryptocurrency beyond its borders in recent years, to include bans on cryptocurrency exchanges and crypto miners. However, over recent months, it is allowing this segment of the overall blockchain innovation to develop within the autonomous Chinese territory of Hong Kong. In fact, it’s actively encouraging it. It’s quite a savvy move by the Chinese who don’t want their citizens using decentralized cryptocurrency generally but are quite happy to still participate on a global level in that sector, by having Hong Kong make efforts to become a regional crypto hub.A second strand to its overall strategy appears to be a concerted effort to expand the user base within China of the digital yuan, its central bank digital currency (CBDC). A series of initiatives have been rolled out in an effort to bring the CBDC into active use. China remains the global leader in CBDC development, much further along in that process than its international peers.Lastly, it’s strategically pursuing the development of blockchain-related business, just as this initiative in Fuzhou indicates. The local government initiative is not an isolated one. Last Wednesday, China’s National Blockchain Technology Innovation Center was formally launched. As far back as 2019, Beijing-based smart contract platform Trias has been assisting authorities in Fuzhou in utilizing blockchain in an effort to better manage its electrical grid infrastructure.

news
Web3 & Enterprise·

Feb 22, 2024

Korbit holds an education session on AML for its employees

Korbit, one of South Korea’s leading crypto exchanges, has recently conducted an education session on anti-money laundering (AML) for its employees, local tech media outlet ZDNet Korea reported.  Held in the office lounge of Korbit, the session was led by Hwang Seok-jin, an expert in financial crime and anti-money laundering regimes. A professor at the Graduate School of International Information Protection of Dongguk University, he has served as a compliance officer and a consultant at Digital Asset eXchange Alliance (DAXA), a group consisting of five leading cryptocurrency exchanges in South Korea.  Photo by Viacheslav Bublyk on UnsplashEmphasis on the Virtual Asset User Protection Act  Mr. Hwang informed Korbit’s employees about the upcoming Virtual Asset User Protection Act, effective July, highlighting guidelines for investor protection, prohibitions against unfair transactions and the financial regulators’ authority and oversight. The session especially focused on explaining the Virtual Asset User Protection Act, given that the Act would deeply influence many departments of Korbits ranging from the accounting and finance unit handling customer deposits to blockchain-related units responsible for the custody of virtual assets.  Korbit maintains a no-negotiation policy that bars projects from interacting with exchange employees prior to their tokens being listed. This policy enhances the transparency of Korbit’s evaluation process, ensuring that the exchange assesses projects impartially, without third-party influence or external pressures. After listing an asset, Korbit conducts quarterly risk assessments on all crypto assets traded on the platform. Additionally, it plans to adopt a stricter approach to internal controls to enhance customer protection, in line with the upcoming enactment of the Virtual Asset User Protection Act. 

news
Loading