Blockchain interoperability protocol Socket reported a security breach on Tuesday that resulted in over $3.3 million in losses. The incident impacted wallets that had granted infinite approvals to Socket contracts. It was attributed to a vulnerability in user input validation.
The exploit was linked to a specific route in the system that had been added just three days before the attack. As per blockchain security firm PeckShield, the problematic route has since been deactivated to prevent further misuse.
Socket identified the issue
In response to the breach, Socket said it has identified the vulnerability in user input validation. The hack affected its Bungee bridging aggregator.
Today’s hack on @SocketDotTech results in the loss of >$3.3m.
The bad route exploited in the hack was added 3 days ago and is now disabled. Here are related txs: – add route tx: https://t.co/lxw7iA1kn4– disable route tx:https://t.co/QMHfI4YeuU
The hack is due to… https://t.co/QdBBgVF287 pic.twit
We współpracy z: https://coingape.com/socket-loses-3-3-million-in-hack-due-to-input-validation-flaw/