Socket protocol loses $3.3M in confirmed approval exploit
Cross-chain protocol Socket has been exploited, and $3.3 million has been drained from contracts associated with it, according to a Jan. 16 social media post from the team. Socket has paused all contracts to prevent further losses.
Urgent
— Socket (@SocketDotTech) January 16, 2024
Socket has experienced a security incident which affected wallets with infinite approvals to Socket contracts.
We have identified the issue have paused the affected contracts.
We’re working on the situation will keep you informed with regular updates next steps.
“Urgent. Socket has experienced a security incident which affected wallets with infinite approvals to Socket contracts,” the post stated. “We have identified the issue have paused the affected contracts.”
Socket is a cross-chain infrastructure protocol used by many Web3 apps, including Synthetix, Lyra, Kwenta, Superform, Plasma Finance and Level Finance.
Blockchain analyst Spreekaway reported the incident from their X account. According to them, the attacker used a token approval from an Ethereum address ending in 97a5 to carry out the exploit. Spreekaway recommended that users revoke all approvals from this address, which they claim shows up as “Socket: Gateway” on Etherscan. Socket claimed that it paused contracts and that “users don’t need to do ANYTHING.”
Related: Gamma attempts to negotiate with hacker after $3.4M exploit
Phishing scammers appear to be taking advantage of the chaos to get new victims. In a reply to Socket’s official post, a fake Socket account posted a link to a malicious app and urged users to revoke their approvals using another malicious app that was also provided. The fake account contained the misspelled X handle @SocketDctTech instead of the correctly spelled @SocketDocTech. The fake account was removed from X within minutes of the post.
Phishing account on X claiming to be Socket. Source: XDune Analytics user Beetle has set up a dashboard to track all losses from the attack.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Law firm demands Pump.fun remove over 200 meme coins utilizing its IP
Share link:In this post: Burwick Law and Wolf Popper issued a cease and desist letter to Pump.fun, demanding the removal of over 200 meme coins allegedly infringing on their intellectual property. The firms claim that Pump.fun allowed the creation of meme tokens spoofing their brands as retaliation for a class-action lawsuit filed against the platform on Jan. 30. Despite mounting legal challenges, Pump.fun continues to see record-breaking trade volumes largely driven by Trump-related meme coins.
US Bank reports $24 million holdings in Bitcoin ETFs in latest SEC filing
Share link:In this post: US Bank reported $24 million holdings in Bitcoin ETFs in its latest SEC filing, an increase of $10 million since its last filing. Goldman Sachs announced it held Bitcoin ETFs of over $400 million across different funds last year. US-listed spot Ethereum ETFs recorded increased inflows amid the overall market dip.
Trump Coin’s Time Is Over? FXGuys Poised to Set New Growth Records in 2025