Socket / Bungee hack — January 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 16, 2024 |
| Target type | Cross-chain bridge |
| Loss | $3,300,000Price at time of incident |
| Recovered | $2,300,000 |
| Method | Contract logic errorA recently added route on the SocketGateway router exposed a performAction() function that passed user-supplied swapExtraData into a low-level .call() without validating it, and whose balance check did not account for the caller transferring zero wrapped ETH. The attacker injected arbitrary calldata so the gateway executed transferFrom against tokens victims had approved, up to their approval limits. |
| Chains | Multiple chains |
| Outcome | Users reimbursed |
What happened
On 16 January 2024 an attacker drained about $3.3 million from wallets that had granted token approvals to Socket, the cross-chain infrastructure layer behind the Bungee bridging front end. The funds were not taken from a protocol treasury but from individual users' wallets, using approvals they had already given the router.
The vulnerability sat in a recently added route on Socket's SocketGateway contract. According to CertiK's analysis, that route's performAction() function made unvalidated, direct use of a low-level .call() with external user-provided swapExtraData, and its balance check failed to account for a caller transferring zero wrapped ETH. That allowed the attacker to inject arbitrary calldata and have the gateway execute transferFrom on any token a victim had approved, up to the approval limit. CertiK counted 230 affected wallets across two attack contracts and itemised the haul as roughly $2.5 million in USDC from 127 victims, 42.48 WETH, 347,006 USDT, 2.89 WBTC, 13,821 DAI and 165,357 MATIC, with the largest single loss 656,000 USDC. SolidityScan's independent analysis reached the same root cause, noting the function did not handle a zero-WETH transfer. Security researcher speekaway publicly flagged the draining transactions around 18:20 UTC.
Socket disabled the vulnerable route, paused bridging, and restarted operations the following day. On 23 January it said it had recovered 1,032 ETH, reported by The Block as worth about $2.3 million at the time and by ChainCatcher as about $2.2 million. Socket then announced full compensation for 232 affected users across five assets, funded by the recovered ETH plus roughly $1.1 million contributed by Socket itself. No actor has been identified.
Sources
- CertiKSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- ChainCatcherSecondary · retrieved 2026-08-01
- SolidityScanSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Socket / Bungee hack — January 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/socket-bungeehttps://itokenly.com/hacks/socket-bungeePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.