{"id":69682,"date":"2024-01-24T06:43:07","date_gmt":"2024-01-24T10:43:07","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=69682"},"modified":"2024-01-24T06:43:10","modified_gmt":"2024-01-24T10:43:10","slug":"socket-protocol-recovers-1032-eth-stolen-from-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/socket-protocol-recovers-1032-eth-stolen-from-hack\/","title":{"rendered":"Socket Protocol Recovers 1032 ETH Stolen From Hack"},"content":{"rendered":"\n<p><a href=\"https:\/\/coinscreed.com\/staging\/binance-halts-support-for-multichain-cross-chain-bridge-tokens.html\" target=\"_blank\" rel=\"noreferrer noopener\">Cross-chain bridge <\/a>Socket protocol has recovered two-thirds of the stolen ETH funds in a recent breach, which led to the loss of about $3.3M.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"817\" height=\"537\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-111.png\" alt=\"Socket Protocol Recovers 1032 ETH Stolen From Hack\" class=\"wp-image-69686\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-111.png 817w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-111-300x197.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-111-768x505.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-111-750x493.png 750w\" sizes=\"(max-width: 817px) 100vw, 817px\" \/><figcaption class=\"wp-element-caption\">Socket Protocol Recovers 1032 ETH Stolen From Hack<\/figcaption><\/figure>\n\n\n\n<p>The socket protocol's official X account has reported the recovery of 1,032 Ether, valued at $2.3 million, out of a total of $3.3 million stolen. Soon, the protocol will disclose a distribution and recovery strategy for consumers. Additionally, Socket expressed gratitude to several on-chain analytics accounts for recuperating the funds.<\/p>\n\n\n\n<p>The perpetrator executed the exploit on January 16 using a token approval originating from an <a href=\"https:\/\/coinscreed.com\/staging\/ethereum-address-activity-drops-to-two-year-low-eth-price-below-1800.html\" target=\"_blank\" rel=\"noreferrer noopener\">Ethereum address <\/a>concluding in 97a5. The vulnerability affected wallets that granted unrestricted approvals to Socket contracts.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">FUND RECOVERY UPDATE<br><br>We have successfully recovered 1032 ETH from the funds involved in the incident on 16th Jan.<br><br>We will release a recovery & distribution plan for users soon.<br><br>Big shoutout to everyone who helped us from Seal911, Slowmist, Hexagate, & others:<a href=\"https:\/\/twitter.com\/samczsun?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@samczsun<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>\u2026<\/p>&mdash; Socket (@SocketProtocol) <a href=\"https:\/\/twitter.com\/SocketProtocol\/status\/1749734794320363802?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">January 23, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p>The vulnerability caused net losses of approximately $3.3 million for 219 users. The <a href=\"https:\/\/coinscreed.com\/staging\/how-cross-chain-compatibility-enhances-smart-contract-capabilities.html\" target=\"_blank\" rel=\"noreferrer noopener\">cross-chain interoperability<\/a> protocol successfully detected and remedied the vulnerability within hours of the exploit, restoring functionality to the bridge within twenty-four hours.<\/p>\n\n\n\n<p>The assailant exploited the over-approval vulnerability of the Socket platform to deplete assets until the authorized limit of each user was exhausted. The assailant exploited never-bridged pre-approved balances. To prevent the loss of these unused limits, users would have been required to revoke authorization proactively.<\/p>\n\n\n\n<p>The vulnerability in the SocketGateway contract was exploited, according to data analytics firm PeckShield, due to incomplete validation of user input; users who had approved the compromised contract were susceptible to the flaw. <\/p>\n\n\n\n<p>Additionally, the security firm stated that the evil gateway was activated three days before the breach. During that period, <a href=\"https:\/\/etherscan.io\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Etherscan <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>advised users to withdraw all authorizations for this IP address, denoted as &#8220;Socket: Gateway.&#8221;<\/p>\n\n\n\n<p>The compromise extended beyond the initial depletion of funds. According to the X post from Socket, phishing scammers also posted a link to a malicious application through a sham Socket account. They encouraged users to revoke their approvals using another malicious application.<\/p>\n\n\n\n<p>Interoperability protocols, also known as cross-chain bridges, are of the utmost importance in facilitating the communication between decentralized protocols. <\/p>\n\n\n\n<p>Nevertheless, these bridges have emerged as a principal target for malicious actors. In recent years, some of the most significant <a href=\"https:\/\/coinscreed.com\/staging\/how-decentralized-exchanges-are-redefining-financial-sovereignty.html\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized finance breaches <\/a>have transpired on cross-chain bridges.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cross-chain bridge Socket protocol has recovered two-thirds of the stolen ETH funds in a recent breach, which led to the loss of about $3.3M. The socket protocol&#8217;s official X account has reported the recovery of 1,032 Ether, valued at $2.3 million, out of a total of $3.3 million stolen. Soon, the protocol will disclose a [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":69686,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[5562,5817,13134,18028],"class_list":["post-69682","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-eth-2","tag-hack-2","tag-cross-chain-bridges","tag-socket-protocol"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/01\/image-111.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/69682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=69682"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/69682\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/69686"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=69682"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=69682"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=69682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}