Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

Aug 12, 2025

Japan’s Soramitsu working on CBDC pilot in Pakistan

Japanese blockchain infrastructure firm Soramitsu has been contracted by the State Bank of Pakistan (SBP) to work on a pilot program for the digital Pakistani rupee. Pakistan originally announced its intention to pursue a central bank digital currency (CBDC) or digital rupee back in 2019. However, unlike other Asian nations such as China, Cambodia and Thailand, it has not taken much action to progress such a digital currency since then.SBP Governor Jameel Ahmad spoke at the Reuters NEXT Asia Summit in Singapore last month, outlining that the South Asian country was moving towards the establishment of a digital rupee and “building up [its] capacity” to launch it, and that a pilot project would be the next step. According to a report published by Nikkei Asia on Aug. 12, that pilot project is now underway.Photo by Hamid Roshaan on UnsplashCBDC specialistSoramitsu already has a wealth of experience in this field. In 2023, it signed a memorandum of understanding with the Laotian central bank to launch a proof-of-concept CBDC project, with the Tokyo-headquartered company going on to play a pivotal role in the issuance of Laos’ Digital Lao Kip.In Cambodia, it partnered with the National Bank of Cambodia to bring about the establishment of Bakong, Cambodia’s CBDC-like payment system. The company is also involved in CBDC projects in Papua New Guinea and the Solomon Islands, while spearheading a project aimed at enabling seamless cross-border payments among Asian countries. Japanese fundingIn the case of Pakistan’s pilot project, Soramitsu’s CBDC platform will facilitate the digital rupee while funding is being provided by the Global South Future-Oriented Co-Creation Project, an initiative from Japan’s Ministry of Economy that seeks to promote the formation of co-creation business models. Infrastructure, such as the internet and power, can be unstable in some parts of Pakistan. Consequently, the proposed CBDC will incorporate the ability for the user to transact with it using their smartphone, even if the phone doesn’t have an active internet connection. Digital transformationMasato Toriya, an associate professor at Tokyo University of Foreign Studies and an expert on Pakistan, outlined the behavioral change that would be required in getting Pakistanis in rural areas to use such a currency. He stated: “Many transactions in rural areas are cash-based, even for wage payments, and the rate of people with bank accounts is low."  However, cash-based systems have significant overheads, and it's thought that a CBDC could reduce such costs considerably. Last month, the Pakistan Institute of Development Economics published an article written by Dr. Ahmed Fraz, an assistant professor of finance with the organization, in which he claimed that the digital rupee pilot project is part of a “profound digital transformation” that Pakistan is moving towards.  Dr. Fraz asserted that a CBDC would enhance financial inclusion in Pakistan through the reduction of transaction fees, digitization of welfare payments and the financial inclusion of millions of unbanked citizens within the formal economy.He added that the digital rupee “is not intended to replace existing payment systems immediately but to complement platforms” and to modernize Pakistan’s financial architecture.

news
Web3 & Enterprise·

Sep 01, 2023

Bitay Ventures into Expanding UAE Crypto Market

Bitay Ventures into Expanding UAE Crypto MarketTurkey’s Bitay, a cryptocurrency exchange headquartered in Istanbul, has taken the decision to enter the United Arab Emirates (UAE) market.The company announced the development via a press release published on Thursday.Bitay General Manager Niyazi Yilmaz expressed his satisfaction in having made the move, stating: “The UAE provides a stable regulatory environment for crypto exchanges. It will serve as more than just a market for Bitay, it will be our technology base, central to our global blockchain strategy.”Photo by Aldo Loya on UnsplashGovernment-aided kickstartBitay sprang to life in 2018 following the award of a research grant by the Turkish government. The business has been operational in Turkey over the course of the past five years, but took the decision to expand on a global basis in 2021. The upshot of that decision saw the company obtain a Money Services Business (MSB) license in 16 states in the United States. Beyond that, the firm has made efforts to extend its services to customers across Europe, Asia, Africa, and the Americas.Last year, Bitay entered the Indian market, and as part of that process, it established an office in Gurgaon. At that time, the company claimed that India, the Turkic countries, Eastern Europe, the Balkans, and selected countries in the Middle East and North Africa (MENA) were its priority markets.Stablecoin USPThe company feels that it has something additional to offer the UAE market by comparison with other platforms that will provide it with a unique selling proposition (USP). It will also offer AEDD, a stablecoin that is pegged to the UAE's local currency, the United Arab Emirates Dirham (AED). Yilmaz explained: “AEDD is not just a stable coin, but a testament to the investment and trust we place in the UAE’s digital future.”To further bootstrap the launch of the platform within the UAE, Bitay is offering some preliminary incentives to encourage UAE residents to use the service. To that end, it’s launching an “Advantageous 2nd Sales Period” campaign. The offering will incorporate 25% discounts on its native exchange token, accompanied by a yield bonus of up to 30% on USDT-based investments.Native token offeringThe company claims that its native token achieved a 330% surge in value within its first year. That said, exchange tokens have been the subject of controversy more recently. The reliance of failed cryptocurrency exchange FTX on its native FTT token was a key factor in the downfall of the platform in 2022. Similar concerns have been raised with regard to global crypto exchange Binance relative to its native BNB token, albeit that any such assertions remain a matter of speculation.A progressive regulatory approach to virtual assets over the course of the past 12 months in the UAE has seen proponents of digital currency heap praise on the country. It has also led to a number of sizable crypto platforms attaining licensing in Dubai and Abu Dhabi, while others have established offices or headquarters within the UAE.

news
Web3 & Enterprise·

Jul 19, 2023

AIITONE Partners with FIDES Development for Real Estate Tokenization

AIITONE Partners with FIDES Development for Real Estate TokenizationAIITONE, a South Korean blockchain-based fintech company, has announced a partnership with FIDES Development, a real estate developer, to enhance their collaboration in the security token sector, as reported by local outlet Hankook Economy TV.FIDES Development has been undertaking various initiatives within the real estate sector, including the identification of underlying assets for security tokens, the development of virtual reality-based show houses, and the implementation of artificial intelligence-powered property technology. In order to support FIDES in these endeavors, AIITONE will provide its advanced fintech services.Photo by Jiho Choi on UnsplashReal estate tokenizationThe objective of the collaboration between the two companies is the tokenization of real estate properties. FIDES Development has developed a wide range of projects, including apartments, offices, and multi-purpose complexes. One of their current projects is a 39-floor accommodation building in Gangwon Province.Legalizing security tokensGiven the accelerating legislative process associated with legalizing security tokens in the National Assembly, construction and development companies are increasingly interested in the fractional investment industry.Both AIITONE and FIDES Development expressed their excitement about this partnership, as they believe it will enable them to identify valuable real estate assets and tokenize them, thus creating innovative and secure investment opportunities.Notably, Kim Seung-bae, CEO of FIDES Development, is also the chairperson of the Korea Developer Association (KODA), which has trained around 18,000 professionals in the field. KODA serves as a legal organization representing South Korea’s real estate development industry.Similar developments in JapanMeanwhile, similar developments have been observed in Korea’s neighboring country, Japan. In May, Mitsui & Co. Digital Asset Management introduced Alterna, a security token platform with a primary focus on real estate. Alterna has democratized investment opportunities that were previously inaccessible, enabling individuals to invest with a minimum of 100,000 yen. The platform garnered substantial interest from Japanese investors, amassing over 10,000 pre-registrants ahead of its official launch.

news
Loading