logo

Socket Tech Incident Analysis

ID: cf20f69b-252c-5d0e-829e-92a1b98f3740

STIX ID: report--cf20f69b-252c-5d0e-829e-92a1b98f3740

Feed Name: CertiK Blog

Threat Score
78/100

Date Published: 2024-01-18

Date Updated: 2026-06-11

...
...

On 16 January 2024 an attacker exploited a recently added router (routeAddress 0xcc5f) in the Socket gateway by supplying malicious swapExtraData to the performAction function, which used an unvalidated .call() and allowed arbitrary execution that invoked transferFrom on tokens users had previously approved to the SocketGateway. The exploit involved two attacker contracts and drained assets from 230 wallets (notable losses include ~3.3M by the largest victim and ~2.5M USDC from 127 victims), with stolen funds consolidated in the exploit wallet; Socket disabled the vulnerable route after the abuse was detected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.