Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Web3 & Enterprise·

May 09, 2023

Dunamu & Partners Invests $109M in 60 Promising Startups

Dunamu & Partners Invests $109M in 60 Promising StartupsInvestment firm Dunamu & Partners (D&P), a subsidiary of South Korean cryptocurrency exchange Upbit’s operator Dunamu, announced that it has made 144.4 billion KRW ($109 million) investments in 60 promising startups, as per economic news media Moneytoday.Photo by Precondo CA on UnsplashDiversified portfolioHaving commenced its operations five years ago, the investment company started investing in fintech and blockchain domains and later diversified its investments into other cutting-edge fields such as artificial intelligence (AI) and data management.AI and data managementA D&P official said that more than half of the investment (52%) has been allocated towards AI and data management. The company made initial investments in nascent startups and continued to provide additional funds to support their noticeable growth.One of the best cases is Korea Credit Data (KCD), the company behind retail revenue management solution Cashnote. After receiving strategic investment from D&P in 2018, KCD secured another 35 billion KRW ($26.4 million) last October to turn into a unicorn company, elevating its status to a unicorn company — a privately-owned startup valued at over $1 billion.Other notable companies in D&P’s portfolio include cloud-based foreign exchange payment solution Travel Wallet, AI-driven investment tech provider Qraft Technologies, and AI chip design firm Rebellions.Positive social impactD&P has also made investments in areas that generate positive social impact. D&P has committed 10 billion KRW ($7.6 million) each to whole-genome sequencing analysis company Genome Insight and knowledge-sharing platform Classum.Investments with capitalD&P invests entirely with capital and does not rely on funds for financing its investments. D&P CEO Lee Kang-joon emphasized the firm’s preemptive monitoring of market trends and its persistent investment strategy in the quest to identify the next industry trailblazer.

news
Policy & Regulation·

Oct 24, 2023

Korea’s Crypto Exchange Group Hires Data Security Professor as Advisor

Korea’s Crypto Exchange Group Hires Data Security Professor as AdvisorThe Digital Asset eXchange Alliance (DAXA) — a group consisting of the top five South Korean cryptocurrency exchanges: Bithumb, Coinone, Gopax, Korbit, and Upbit — announced on October 24 (local time) that it has appointed an information security professor as one of its advisors.Photo by Heng Films on UnsplashInvestor protection expertDr. Hwang Seok-jin, a professor at the Graduate School of International Affairs and Information Security at Dongguk University, is widely recognized for his expertise in investor protection. He has previously held positions with the ruling People Power Party’s Digital Asset Special Committee, the Korean Army, the Korea Coast Guard, and the Korea Association of Anti-Money Laundering.Upcoming regulation rolloutDAXA Vice Chairman Kim Jae-jin said, “The alliance has decided to bring on a new advisor ahead of the upcoming implementation of the Virtual Asset User Protection Act. Given his wealth of experience and expertise, we expect that Professor Hwang will contribute to significantly enhancing the objectivity and practicality of DAXA’s self-regulation.”The advisory term at DAXA is one year, which means the new advisor’s tenure will extend until October 24, 2024.

news
Policy & Regulation·

Sep 12, 2025

China funds research on stablecoin risks to financial system

China’s leading science foundation has initiated a research program to examine the effects of stablecoins, reflecting concerns that such digital currencies could pose a risk to the nation’s financial system and its fiat currency. According to the South China Morning Post, the National Natural Science Foundation of China (NSFC) is now offering grants for studies focused on stablecoins and the creation of cross-border monitoring frameworks. The foundation expressed that the unmonitored circulation of private stablecoins, particularly those pegged to the U.S. dollar, could weaken capital controls and present a potential challenge to the yuan. This initiative emerges as governments around the world, from the U.S. to regional financial centers, are actively developing rules for the digital asset sector.Photo by  Christian Lue on UnsplashStrategic research and internal debateThe NSFC will fund the projects with grants valued between 200,000 and 300,000 yuan ($28,042 to $42,063). Researchers are expected to complete their work within a year and deliver policy recommendations on how China can manage the challenges posed by global stablecoins and contribute to digital finance governance. The deadline for applications is Oct. 9. This research program is set against a backdrop of internal discussion in China regarding the possible launch of a yuan-backed stablecoin. While some economists support the idea of boosting the yuan's international profile, Bloomberg noted that former central bank governor Zhou Xiaochuan has advised caution. He recently said the high efficiency of China's current payment systems and warned that financial stability could be threatened by speculation in the stablecoin market. Analysts believe any state-sanctioned yuan stablecoin would likely be confined to offshore markets and tied to the offshore CNH. Global regulatory landscapeChina’s examination of stablecoins is part of a broader global trend of increased regulatory focus on the asset class. In Hong Kong, a new ordinance took effect on Aug. 1, creating a mandatory licensing system for stablecoin issuers under the oversight of the Hong Kong Monetary Authority. Other Asian nations are also taking action. South Korea’s government is reportedly exploring a model for a won-pegged stablecoin involving a consortium of banks and non-bank entities. Separately, Cointelegraph reported that Kyrgyzstan has introduced legislation outlining a regulatory framework for such assets. Developments are also accelerating in the U.S., where the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act was signed into law, creating a federal structure for stablecoin oversight. On a commercial level, a Minnesota-based credit union, St. Cloud Financial, intends to introduce its own stablecoin later this year, a move highlighted by Cointelegraph. This token, named Cloud Dollar (CLDUSD), is designed to integrate with the credit union's banking system to facilitate faster and cheaper transactions for its members within a regulated environment.

news
Loading