Bungee Hack

TOTAL LOST $3.3M
Medium Access Control Attacks Ethereum

What happened

Socket's Bungee protocol lost about $3.3 million from Ethereum user wallets after a newly added routing implementation allowed attacker-controlled calldata to invoke transferFrom against existing SocketGateway approvals. Socket later reported recovery of 1,032 ETH, worth about $2.3 million at the time.

Technical Root Cause

WrappedTokenSwapperImpl.performAction directly executed caller-controlled swapExtraData without validating its calldata. The zero-WETH path bypassed the balance check, allowing arbitrary transferFrom calls to use pre-existing token approvals granted to SocketGateway.

Case & protocol details

Classification Access control / arbitrary external call
Smart Contract Language Solidity

Attack Timeline

The attacker called SocketGateway's fallback routing selector through an attack contract. The gateway delegated to a newly added WrappedTokenSwapper route, whose performAction path executed caller-controlled swapExtraData without adequate validation.

A zero-WETH route bypassed the intended balance check and injected transferFrom calls against wallets that had approved SocketGateway. The attacker repeatedly drained approved USDC, WETH, USDT, WBTC, DAI, and MATIC from approximately 230 wallets.

Funds Recovery

69.7%

Recovered

$2.3M

Net Loss

$999,900

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.