Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Policy & Regulation·

Aug 18, 2023

Dispute Embroils Bitget in Legal Battle With Crypto Influencer

Dispute Embroils Bitget in Legal Battle With Crypto InfluencerBitget, the crypto exchange registered in Seychelles, finds itself entangled in a legal dispute with prominent crypto influencer Evan Luthra.Photo by Tingey Injury Law Firm on UnsplashAccount freezing allegationsThe conflict stems from Luthra’s allegations of account freezing and loss of funds after a token listing incident in March. Luthra has filed a lawsuit against Bitget, accusing the exchange of withholding $200,000 in Tether (USDT) without adequate explanation, while also freezing his account.The legal drama follows Luthra’s involvement with the Reel Star project, where he served as an advisor for the platform which is aimed at creators. As compensation for his collaboration with the project, Luthra received Reel Token (REELT), the project’s utility token.Bitget alleged market manipulationUpon the listing of REELT tokens, Luthra reportedly sold 1.3 million tokens on Bitget. In response, Bitget claims it faced a manipulative attack orchestrated by a group of traders attempting to profit from market manipulation immediately after the token’s listing. This allegedly caused a significant drop in the token’s price, prompting Bitget’s decision to freeze Luthra’s account.Bitget states that it contacted Luthra seeking an explanation for the suspicious trading behavior. Luthra acknowledged the token sale but failed to provide satisfactory reasons for his actions, according to Bitget’s version of events. The exchange maintains that user protection is its foremost priority and that it takes swift action against illegal or fraudulent behaviors.$16 million damages claimLuthra refutes the allegations, asserting his innocence and citing alleged approval from Reel Star’s Co-Founder Navdeep Sharma for his token sale plans. He seeks a substantial $16 million in damages, in addition to the frozen funds. Luthra claims that Bitget unjustly deprived him of his tokens, asserting his status as a fully KYCed user entitled to access his holdings.In the aftermath of the incident, Bitget conducted an investigation and offered a compensation plan for affected clients. Gracy Chen, Bitget’s Managing Director, emphasized the exchange’s commitment to user protection and its actions against illicit activities on its platform. Addressing the matter on Twitter, Chen didn’t hold back in her commentary on Luthra, stating that he “has a history of fraudulent activities,” which she says were exposed by crypto journalist CoffeeZilla.The legal dispute has ignited debates within the crypto community. Supporters of Luthra contend that his case underscores broader issues faced by users of centralized exchanges, shedding light on the need for improved user rights and protection. On the other hand, some argue that Bitget acted appropriately to safeguard its users and the market integrity.CZ brought into the disputeThe legal battle has attracted attention from influential figures in the crypto industry. Against a backdrop of a very public airing of the dispute on Twitter, in a recent tweet Luthra invited Changpeng Zhao (CZ), the CEO of Binance, to respond to Luthra’s claim that Bitget spreads rumors about other exchanges. CZ was having none of it, writing: “You should talk to them, right? We are not a regulator for other exchanges.”The case highlights the intricate challenges surrounding market manipulation and token listings within the crypto space. As it unfolds, the outcome could potentially set a precedent for similar situations involving token listings, market manipulation, and user protection.

news
Web3 & Enterprise·

Aug 10, 2023

Foblgate Strengthens Anti-Cybercrime Measures with Chainalysis Solutions

Foblgate Strengthens Anti-Cybercrime Measures with Chainalysis SolutionsKorean crypto exchange Foblgate last Thursday announced its adoption of virtual asset data analysis solutions from blockchain data analysis firm Chainalysis, which has significantly enhanced its ability to combat illegal money laundering of virtual assets and cybercrime.“As crimes involving virtual assets continue to rise, the introduction of Chainalysis’ solutions empowers us to address a wider range of diverse and advanced virtual asset-related crimes,” said Ahn Hyun-jun, CEO of Foblgate.Photo by GuerrillaBuzz on UnsplashChainalysis’ specialized solutionsChainalysis provides data, software, services, and research to governmental agencies, exchanges, financial institutions, insurance companies, and cybersecurity firms all over the world, aiding in solving high-profile criminal cases and expanding consumer access to cryptocurrency safely.Foblgate will use two of its products, Know Your Transaction (KYT) and Reactor, to strengthen safety and security measures on its exchange platform.KYT is a cryptocurrency compliance product that combines blockchain technology, a simple interface, and a real-time application programming interface (API) to map data, monitor crypto transactions, and provide safe access to decentralized finance.Meanwhile, Reactor is an investigation software that connects cryptocurrency transactions to real-world activity. This allows users to visualize cryptocurrency flows and trace transactions across blockchains.Both solutions automatically detect patterns of potential high-risk activities then issue alerts accordingly and link numerous addresses to actual entities (individuals or organizations associated with virtual asset wallet addresses.)By integrating this technology, Foblgate can restrict deposits and withdrawals made by high-risk entities, including unregistered overseas virtual asset exchanges. It can also ensure transparency in virtual asset trading within its domain.Taking security measures a step furtherFoblegate is also taking other measures to further earn trust as a secure exchange by bolstering its countermeasures to cybercrime. Notably, it has established a partnership with GTOne, a company specializing in governance and compliance solutions including anti-money laundering (AML). Through this collaboration, it will be able to thoroughly comply with the Act on Reporting and Using Specified Financial Transaction Information.This strategic move towards innovative blockchain data analysis solutions not only underscores Foblgate’s commitment to regulatory compliance and user security but also a proactive stance against emerging challenges in the realm of virtual assets and cybercrime.

news
Web3 & Enterprise·

Aug 09, 2023

Galaxia Metaverse Joins Hands with MVL Foundation to Expand Blockchain Ecosystems

Galaxia Metaverse Joins Hands with MVL Foundation to Expand Blockchain EcosystemsSouth Korean blockchain company Galaxia Metaverse said Wednesday it will collaborate with MVL Foundation, a blockchain-based mobility enterprise in Singapore, to advance their respective blockchain ecosystems by enabling the use of their tokens, Galaxia (GXA) and MVL, within them.Photo by Shubham Dhage on UnsplashPromoting token utilizationAs of now, MVL tokens can be used for purchasing discount coupons for TADA, MVL Foundation’s ride-hailing service. Through the partnership, GXA tokens will also be able to purchase TADA discount coupons through MVL’s cryptocurrency wallet, Clutch Wallet. Discussions are currently underway regarding more joint ventures, such as integrating the MVL token with staking products offered by Galaxia’s own digital wallet.“The MVL token is already being used by millions of mobility service users with Southeast Asia as its base. Through this partnership, we expect that our global expansion will be accelerated as we bring more users to our ecosystem,” Galaxia emphasized.Expanding the Southeast Asian user baseMVL Foundation operates its mobility services mainly in Southeast Asian countries including Singapore, Cambodia, and Vietnam. Its ride-hailing service TADA is the second-largest of its kind in Singapore. This ecosystem is connected via blockchain, enabling participants to receive rewards in accordance with their activities and ultimately forging a Web3 mobility system.Subsequently, Galaxia intends to take advantage of MVL’s solid footing in Singapore to push joint localized marketing within the country.“We are planning to develop various solutions, rewards, and service integrations with MVL by leveraging our strengths, expertise, and networks,” Galaxia said.Meanwhile, throughout this year, Galaxia has been expanding its blockchain ecosystem in other ways. Notably, it has collaborated with industry leaders such as Korean NFT exchange Pala and karaoke app Somesing.

news
Loading