Socket Hack
Check if your address is affected.
Socket is an interoperability protocol that moves tokens between blockchains. It powers the Bungee Exchange bridge and bridging features in other apps such as Rainbow Wallet, so many users approved its main contract to spend their tokens. Three days before the attack, Socket added a new feature to this contract for swapping tokens. According to Halborn, an early version of that code went live instead of the version that had been reviewed. On 16 January 2024, an attacker found that it did not check the instructions it was given, and used it to take tokens straight from wallets that had approved Socket.
The attacker drained about $3.3M from many wallets, all of them on Ethereum, even though the faulty feature was live on seven chains. Socket disabled it about 15 minutes after the first theft and resumed normal bridging the next day. After negotiations, the attacker returned 1,032 ETH, worth about $2.3M at the time, leaving roughly $1M in their hands. Socket then promised to fully compensate affected users, adding about $1.1M of its own funds to the recovered ETH.
The faulty feature was removed and cannot be used anymore, so Socket's contract is safe to use again and approvals to it no longer expose you to this attack. Still, the incident shows how a single bad update to a contract you have approved can put your tokens at risk overnight. It is good practice to avoid unlimited approvals where possible and to revoke approvals for apps you no longer use.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →