Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Sep 14, 2023

Krafton and Naver Z Unveil a Metaverse Joint Venture ‘Overdare’

Krafton and Naver Z Unveil a Metaverse Joint Venture ‘Overdare’Krafton, the developer behind the popular shooter game PlayerUnknown’s Battlegrounds (PUBG), made an announcement on Thursday regarding its collaboration with augmented reality company Naver Z for a metaverse platform project. The official name of their joint venture has been revealed as “Overdare.” Furthermore, its forthcoming metaverse service, previously referred to as Migaloo, will also be rebranded under the name Overdare.Photo by Tima Miroshnichenko on PexelsInvestment breakdownThe total investment in the joint venture amounts to KRW 48 billion (approximately $36 million), with Krafton’s anticipated purchase price standing at KRW 40.8 billion and Naver Z’s expected purchase price at KRW 7.2 billion. Following the acquisition, Krafton will hold an 85% stake in the joint venture, while Naver Z will possess the remaining 15%.Meaning behind ‘Overdare’The company has chosen the English word Overdare to convey two meanings–“dare too much” and “over there,” which has a phonetic resemblance. Through this name, the joint venture aspires to establish itself as a pioneer in the realm of interactive user-generated content (UGC) platforms. Simultaneously, its service aims to provide a place where users can freely and fearlessly express themselves.As a mobile UGC platform, Overdare offers users the ability to craft games of diverse genres, including action RPGs, sports games, and shooting games. Leveraging the power of generative artificial intelligence and the advanced capabilities of Unreal Engine 5, a renowned video game engine, the platform facilitates the streamlined creation of top-notch content. Beyond game development, users can immerse themselves in a wide array of social activities, ranging from personalizing their avatars to engaging in lively conversations.C2E systemOverdare has adopted a create-to-earn (C2E) system within the metaverse, empowering creators to produce their own content, which users can then purchase and own. The trading of these creations is facilitated through non-fungible tokens (NFTs) and blockchain technology. Every transaction that takes place within the metaverse is recorded on the blockchain, and creators are duly compensated based on these transaction records. This system enhances the transparency of transactions and settlements.Compensation in USDCIn pursuit of this vision, Overdare has selected Settlus, a Cosmos-based blockchain developed by Krafton’s subsidiary of the same name, as its mainnet. Settlus has been dedicated to licensing creators’ intellectual property through NFTs on Web2 platforms. As part of this ecosystem, creators have the flexibility to receive compensation in USDC, the US dollar-pegged stablecoin issued by crypto company Circle.Overdare has its sights set on a soft launch of its service in December, followed by the official global release planned for the first half of next year.

news
Policy & Regulation·

Apr 29, 2024

Mainland Chinese restrictions impact BTC and ETH ETFs in Hong Kong

Recent developments in the cryptocurrency market reveal that mainland Chinese citizens will face restrictions in purchasing Bitcoin and Ether exchange-traded funds (ETFs) in Hong Kong. This restriction stems from China's ban on crypto transactions, which has been in effect for several years. Bloomberg data analyst Jack Wang highlighted this issue, indicating that the upcoming launch of spot Bitcoin and Ether ETFs in Hong Kong will not facilitate market access for investors in mainland China.Photo by Traxer on UnsplashSpot Bitcoin and Ether ETFs approved in Hong KongDespite Hong Kong's approval of spot BTC and ETH ETFs, major Chinese asset managers such as China Asset Management, Harvest Global Investments, and Bosera have established these products through their Hong Kong subsidiaries. However, despite their close ties with mainland China, these ETF issuers are unable to offer Bitcoin or Ether exposure to investors within the jurisdiction due to regulatory constraints. Exclusion of mainland Chinese investorsWang emphasized during a Bloomberg webinar that mainland Chinese citizens will not be able to participate in these ETFs, citing a statement from the Chinese State Council issued in September 2021. This statement prohibits financial institutions from engaging in crypto-related transactions, including account creation, fund transfers, and clearing services. As a result, Chinese investors are unlikely to engage with these products in the short term. Impact on regulatory environment and market accessWang expressed skepticism about the potential impact of spot Bitcoin and Ether ETFs in Hong Kong on the regulatory environment in mainland China. He stated that the launch of these ETFs is unlikely to open the crypto market to Chinese investors in the foreseeable future. Thomas Zhu, head of digital assets at China Asset Management, noted that the eligibility of mainland Chinese investors to acquire crypto ETFs in Hong Kong depends on forthcoming regulatory modifications. He highlighted the Mainland-Hong Kong Stock Connect, which allows mainland investors to trade eligible Hong Kong stocks and ETFs since 2014. Comparison with U.S. Bitcoin ETF marketDespite optimism surrounding the launch of spot crypto ETFs in Hong Kong, Bloomberg analyst James Seyffart drew attention to the significant difference in market size between the U.S. and Hong Kong ETF markets. Seyffart pointed out that Bitcoin ETFs in the United States have more assets than all ETFs in Hong Kong combined, emphasizing the vast disparity in market scale and impact. As the launch date for spot Bitcoin and Ether ETFs in Hong Kong approaches, stakeholders continue to monitor regulatory developments and market dynamics closely. 

news
Web3 & Enterprise·

Mar 20, 2024

Korea’s security token group KSTO signs MOU with blockchain developer Metalab

The Korea Security Token Offering (KSTO), a South Korea-based association dedicated to providing compliance guidelines for STO projects, announced on Monday that it signed a memorandum of understanding (MOU) with blockchain company Metalab for STO mainnet development. The news was reported by local media outlet Ajunews. Through the MOU, the two institutions plan to create a blockchain platform for local blockchain companies, catering to their needs for STO issuance.Photo by Kaitlyn Baker on UnsplashThe KSTO is an association aiming to provide consultation services on STO design and development and assist blockchain projects in complying with laws and regulations, contributing to building a healthy blockchain ecosystem. Meanwhile, a member of the KSTO, Metalab is a blockchain firm with expertise in developing crypto tokens and decentralized applications, or DApps. The company is reportedly participating in an STO mainnet development project led by the KSTO.  STO infrastructure catering to Korean firms and investors Mainnet refers to the primary blockchain network where actual crypto transactions take place, such as the Ethereum or Solana platform. Mainnets, which operate on their own based on their independent infrastructures, are highly valued in the crypto markets due to the complexity of developing such networks.  This blockchain mainnet project involving Metalab will offer basic infrastructures that enable large-scale STO transactions, with plans to release features for STO issuance and management in connection with crypto wallets.  An KSTO official stated that the institution aims to support companies willing to issue STOs, from both technological and legal perspectives. The person highlighted the institution’s commitment to creating an STO ecosystem tailored for Korean companies, saying that the project will create a regulation-compliant, user-friendly platform and develop it to a level where it can rival the industry’s leading players like Polymesh, a prominent security token platform.  

news
Loading