Bungee Hack
What happened
Socket's Bungee protocol lost about $3.3 million from Ethereum user wallets after a newly added routing implementation allowed attacker-controlled calldata to invoke transferFrom against existing SocketGateway approvals. Socket later reported recovery of 1,032 ETH, worth about $2.3 million at the time.
WrappedTokenSwapperImpl.performAction directly executed caller-controlled swapExtraData without validating its calldata. The zero-WETH path bypassed the balance check, allowing arbitrary transferFrom calls to use pre-existing token approvals granted to SocketGateway.
Case & protocol details
Attack Timeline
The attacker called SocketGateway's fallback routing selector through an attack contract. The gateway delegated to a newly added WrappedTokenSwapper route, whose performAction path executed caller-controlled swapExtraData without adequate validation.
A zero-WETH route bypassed the intended balance check and injected transferFrom calls against wallets that had approved SocketGateway. The attacker repeatedly drained approved USDC, WETH, USDT, WBTC, DAI, and MATIC from approximately 230 wallets.
Funds Recovery
Recovered
$2.3M
Net Loss
$999,900
Evidence & learning
Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.