Top

Socket's Bungee resumes operations following exploit

Web3 & Enterprise·January 18, 2024, 2:41 AM

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.

https://asset.coinness.com/en/news/73b443a370b79157a0501b9755418a96.webp
Photo by Anna Tarazevich on Pexels

Security incident

Taking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.”

 

The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet.

 

Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets.

 

Pausing contracts

In response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact.

 

@speekaway chimed back in once contracts had been paused, writing:


”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.”

 

Normal service returns

As Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress.

 

Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem.

 

The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval.

 

This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges.

 

In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ.

 

Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures.

 

More to Read
View All
Markets·

Apr 24, 2023

Report: Can Bitcoin Replace Gold As a Safe Asset?

Report: Can Bitcoin Replace Gold As a Safe Asset?In light of the substantial increase in Bitcoin (BTC) prices this year, a report from KB Financial Group in South Korea examined the potential for BTC to replace gold as a safe asset.©Pexels/Michael SteinbergThe study delves into the factors behind the recent BTC price surge and emphasizes the need for caution when considering BTC as an alternative to traditional safe assets.3 drivers behind BTC surgeFrom January 1 to March 31 this year, BTC experienced an impressive return of 71%. This surge can be attributed to three main factors: an anticipated increase in liquidity due to market expectations of unchanged or falling interest rates; central banks supplying liquidity to mitigate risks in the traditional banking system; and concerns over the potential delisting of cryptocurrencies should the US court’s decision on the Ripple-SEC case classify XRP, Ripple’s native token, as securities, prompting investors to shift their focus to BTC.The report suggests that the current BTC boom is more likely a result of short-term arbitrages and social conformity, given the greater information asymmetry in the crypto market, which lacks the disclosure system present in traditional stock markets.Persisting risk factorsLast month, blockchain tracker Whale Alert spotted a transfer of 11,125 BTC from an anonymous address to Binance. The primary reason for moving assets from a private address to an exchange address is to sell them, indicating that investors should keep a watchful eye on Bitcoin trading volumes, particularly for any signs of large sell-offs.Data from the crypto data analysis platform Glassnode revealed that the percentage of the BTC supply that was active over a year ago reached an all-time high of 68% in late March. Historically, such an increase has been associated with falling BTC prices.This year, the BTC supply is set to grow due to the US government’s liquidation of seized BTC. As detailed in a March 31 Cointelegraph article, the US government seized 51,352 BTC in a case related to Ross Ulbricht, the creator of the online black market Silk Road. The government has already sold 9,861 BTC, with the remaining amount expected to be liquidated in four additional portions throughout the year.Binance, the world’s largest crypto exchange by trading volume, has been struggling to find banks in the US to store client funds after crypto-friendly banks Silvergate and Signature closed their doors.Need for cautionAlthough various media sources often portray BTC as a safe asset, the report advises caution in accepting these claims. Although some liken BTC to “digital gold,” the two assets share little in common beyond their finite and scarce nature. In fact, gold and BTC diverge significantly in terms of social consensus, intrinsic value, price volatility, and investor protection.Gold serves as a highly liquid asset with applications in both jewelry and industrial goods, in addition to its role as an investment vehicle. In contrast, BTC’s intrinsic value is still debatable. The price volatility of BTC is also a concern, as evidenced by its 71% spike in the first quarter of 2023, compared to gold’s modest 8% increase. Additionally, gold investment products are regulated by law, whereas BTC is not. The report thus recommends treating BTC as a high-risk product and incorporating it into a diverse investment portfolio.It is worth noting that since the outbreak of the COVID-19 pandemic, the crypto market has demonstrated a stronger correlation with the global stock market in response to negative signals. This trend can be partially attributed to the growing presence of institutional investors in the crypto market, who often sell risky assets first to secure liquidity in the face of unexpected shocks.

news
Policy & Regulation·

Jul 27, 2023

Ripple and the Republic of Palau Collaborate to Mint First PSC Stablecoin

Ripple and the Republic of Palau Collaborate to Mint First PSC StablecoinIn a groundbreaking partnership, the Republic of Palau has teamed up with Ripple Labs to introduce its inaugural stablecoin, the Palau Stablecoin (PSC).This occasion was shared by Jay Hunter Anson, the Director of Palau’s Digital Residency Program and a member of Palau’s Ministry of Finance, who took to Twitter on Wednesday to shed light on the collaboration between the Palau National Treasury and Ripple Labs.The event unfolded at the National Capitol in Ngerulmud, Palau, where representatives from both the Palau National Treasury and Ripple gathered to celebrate the successful launch of the Palau Stablecoin. Anson emphasized that this marks a significant step in their joint exploration of the stablecoin’s potential use cases within the Micronesian island nation.Photo by Kanchanara on UnsplashReducing payment costsPalau’s Ministry of Finance initiated the Stablecoin project to address specific needs within the nation’s financial landscape. By sponsoring this project, the ministry aims to reduce payment costs within the Republic of Palau and enhance access to financial services, especially for underserved communities and various socio-economic groups, utilizing digital solutions.Notably, the Palau Stablecoin operates on the XRP Ledger (XRPL), demonstrating Ripple’s technology as the backbone of this financial initiative.Anson’s tweets also shed light on the meticulous approach taken in developing the Palau Stablecoin. Controlled and limited PSC pilot tests have been conducted to assess the effectiveness and efficiency of the solution co-designed with Ripple. These pilot experiments provide valuable insights into the stability and usability of the Palau Stablecoin before its potential public release.Extensive testingAlready, the Palau Stablecoin pilot program has seen volunteer users actively participating in the testing phase. Videos shared by Anson on Twitter showcased smooth transactions at partner vendors in Palau, promptly confirming the transaction receipts.The successful implementation of the Palau Stablecoin pilot program has drawn attention from the XRP community, and anticipation is building for the official joint press release scheduled for July 27, Thursday morning in Ngerulmud, Palau, as Anson revealed.The collaboration between Ripple and the Republic of Palau was initiated at the end of 2021, with launch originally scheduled to take place in 2022. Ripple has claimed to be in dialogue with in excess of twenty governments relative to enabling central bank digital currency (CBDC) issuance.Given that the island state lacks a functioning central bank and the US dollar is recognized as the primary medium of exchange throughout the country, the creation of a USD-backed stablecoin is a significant achievement resulting from the national stablecoin initiative. The president described this as a “step towards our own central bank digital currency.”There has been plenty of activity in Micronesian nations relative to cryptocurrency in recent times. Tonga is understood to be considering introducing bitcoin as legal tender. The Marshall Islands is considering issuing a CBDC although it is being discouraged by the International Monetary Fund (IMF) in that endeavor. Meanwhile, the government of Vanuatu announced its support for the Satoshi Island project.With a strategic focus on addressing financial needs and enhancing accessibility within Palau, this partnership sets the stage for a new era of digital financial solutions for the Micronesian nation.

news
Policy & Regulation·

Dec 14, 2023

KuCoin resolves lawsuit through settlement and New York market exit

KuCoin resolves lawsuit through settlement and New York market exitKuCoin, one of the largest global cryptocurrency exchanges, has arrived at a comprehensive settlement with the authorities in the state of New York in the United States, agreeing to pay $22 million.Photo by Michael Discenza on UnsplashSubstantial fine and refundsThe settlement not only involves a substantial fine but also includes refunds to New York investors and the cessation of trading activities in the state. This resolution comes amidst an assertive effort by New York authorities to shape and regulate the crypto landscape within the state.According to a statement released by New York Attorney General Letitia James on Tuesday, KuCoin will refund a total of $16.7 million to 177,800 New York investors. In addition to the refunds, KuCoin will pay a $5.3 million fine to the state.The settlement addresses allegations that KuCoin failed to register as a securities and commodities broker-dealer while falsely presenting itself as a cryptocurrency exchange.Taking to social media platform X, James wrote:”My office is making crypto platform @kucoincom pay over $22 million for illegally operating in New York. KuCoin is also banned from doing business in our state. Shady cryptocurrency platforms must play by the same set of rules as everyone else or face the consequences.”At the time of taking action against KuCoin in March, James described the lawsuit as “our eighth action to rein in shadowy cryptocurrency platforms that disregard our laws and put New Yorkers at risk.”Lack of registrationKuCoin, based in the Seychelles, allows investors to trade digital assets through its website and app. However, the state of New York argued that KuCoin could not legitimately claim to be an exchange due to its lack of registration with the U.S. Securities and Exchange Commission (SEC) and the proper designation by the Commodity Futures Trading Commission (CFTC), as mandated by state law.Ranked as the fourth-largest exchange by spot and derivatives trading volume, KuCoin’s KCS token, a profit-sharing token on the platform, has experienced a 39% increase since the start of the week. At the time of writing, it has a unit price of $13.80. This surge is a consequence of the clarity and finality brought about by the settlement, alongside rising expectations for a U.S. exchange-traded fund (ETF) directly investing in Bitcoin, sparking a broader rally in lesser-known cryptocurrencies over the past month.Potential rumorsKuCoin CEO Johnny Lyu took to the X platform on Tuesday to outline details of the settlement. Interestingly, Lyu included this notification:”I also want to give you a heads-up about potential rumors surfacing in the next few weeks. Please stick to the official website of KuCoin for accurate information.”While the settlement may have brought a certain degree of clarity to the KuCoin platform, Lyu’s comment suggests that there may be other issues about to emerge in the short term.The lawsuit against KuCoin is part of a broader regulatory trend in New York, with Attorney General James having previously filed a similar complaint against CoinEx. Additionally, a settlement in January involving crypto companies Nexo Inc. and Nexo Capital Inc. resulted in a financial resolution of up to $24 million for New York and nine other states.

news
Loading