Socket Hack
What happened
The Socket Protocol was exploited on January 16, 2024, which resulted in a loss of approximately $3.3 million worth of assets.
Socket is an interoperability protocol that enables data and asset transfers across chains, with Bungee being a bridge aggregator built on SocketLL by the Socket team. On January 16, 2024, the Socket protocol experienced a security incident affecting wallets with infinite approvals granted to Socket contracts. The exploit's root cause was incomplete validation of user inputs, allowing the attacker to steal funds from users who had approved tokens for the vulnerable contracts. The attack impacted approximately 712 users, with the stolen funds remaining in the attacker's address.
Losses included 165,356 MATIC, 2.8896 WBTC, 42.4753 WETH, and 13,821 DAI, resulting in a total loss of around 3,300,000 USD.
Attacker Address:
https://etherscan.io/address/0x50DF5a22…d39066
Malicious Transactions:
https://etherscan.io/tx/0x591d054a…24ce54
https://etherscan.io/tx/0xc6c3331f…e28fd6
Malicious Contract Addresses:
https://etherscan.io/address/0xa5f1e956…1f1c8e
https://etherscan.io/address/0xf2d5951b…9c05d1
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- analysis Web Archive archive.is
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.