Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn

Socket protocol loses $3.3M in confirmed approval exploit

CointelegraphCointelegraph2024/01/16 23:09
By:Tom Blackstone

Cross-chain protocol Socket has been exploited, and $3.3 million has been drained from contracts associated with it, according to a Jan. 16 social media post from the team. Socket has paused all contracts to prevent further losses.

Urgent

Socket has experienced a security incident which affected wallets with infinite approvals to Socket contracts.

We have identified the issue have paused the affected contracts.

We’re working on the situation will keep you informed with regular updates next steps.

— Socket (@SocketDotTech) January 16, 2024

“Urgent. Socket has experienced a security incident which affected wallets with infinite approvals to Socket contracts,” the post stated. “We have identified the issue have paused the affected contracts.”

Socket is a cross-chain infrastructure protocol used by many Web3 apps, including Synthetix, Lyra, Kwenta, Superform, Plasma Finance and Level Finance.

Blockchain analyst Spreekaway reported the incident from their X account. According to them, the attacker used a token approval from an Ethereum address ending in 97a5 to carry out the exploit. Spreekaway recommended that users revoke all approvals from this address, which they claim shows up as “Socket: Gateway” on Etherscan. Socket claimed that it paused contracts and that “users don’t need to do ANYTHING.”

Related: Gamma attempts to negotiate with hacker after $3.4M exploit

Phishing scammers appear to be taking advantage of the chaos to get new victims. In a reply to Socket’s official post, a fake Socket account posted a link to a malicious app and urged users to revoke their approvals using another malicious app that was also provided. The fake account contained the misspelled X handle @SocketDctTech instead of the correctly spelled @SocketDocTech. The fake account was removed from X within minutes of the post.

Phishing account on X claiming to be Socket. Source: X

Dune Analytics user Beetle has set up a dashboard to track all losses from the attack.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

You may also like

Kamala Harris odds climb to 18% on Polymarket, over $11 million in bets

Cryptobriefing2024/07/03 22:13

Cardano Price Predictions: Is ADA Ready for a 70% Rally in the Coming Days?

ADA has been among the best performing cryptocurrencies in the past week (at least from the top 20 club).

Cryptopotato2024/07/03 22:04

Judge sides with CFTC, deems OHM and Klima commodities in case involving crypto 'Ponzi'-like scheme

Quick Take Sam Ikkurty of Oregon and his company Jafia, LLC made “material misrepresentations,” Judge Mary Rowland of the U.S. District Court for the Northern District of Illinois said in an opinion issued this week. Notably, Judge Rowland also said that OHM and Klima were commodities. That might not be a big deal since they still could be deemed securities, according to one lawyer.

The Block2024/07/03 21:43

This Controversial Meme Coin Jumps by 35% Following an ‘Urgent’ Announcement From Andrew Tate

Andrew Tate urged the token’s holders to increase their exposure in the following hours: here’s why.

Cryptopotato2024/07/03 20:16

‌Spot copy trading

More
AIOnline
AIOnline
insight1000/1000
9937.51%
ROI
Total profit $50681.28
WhaleGo_YouTube
WhaleGo_YouTube
insight500/500
1323.16%
ROI
Total profit $3841.97

Bot copy trading

More
GoldenEgg
GoldenEgg
insight142/150
$8535.66
Total profit
Total subscriber profits $-284.87
BGUSER-FFF8CNJ4
BGUSER-FFF8CNJ4
insight8/150
$4174.08
Total profit
Total subscriber profits $-79.9