A Three-Day-Old Bridge Route Cost Socket's Bungee $3.3M in Approval Drains
Socket's Bungee bridge suffered a $3.3 million loss the day before this report, after an attacker drained wallets that had previously granted approvals to the SocketGateway contract on Ethereum — a reminder of how much risk sits in standing token approvals.
Once the incident was flagged, Socket's team confirmed the exploit and deployed a fix just 14 minutes after the attack started. Wallet provider Rainbow, which relies on Socket's contracts for its in-app bridging feature, alerted its own users as well, recommending they check whether their addresses were exposed and revoke any relevant approvals using RevokeCash's tool.

Coming not long after the roughly $80 million New Year's Eve exploit targeting Orbit, this incident underscores that cross-chain bridges remain a favored target for attackers and require rigorous scrutiny with every contract change. It also raises the question of how a previously identified bug ended up shipped to a production bridge in the first place.
Credit: qckhp, Peckshield, Beosin
How the Exploit Worked
The root cause was insufficient validation of user-supplied input in a new routing path that had been added to the bridging contract only three days before the attack. The contract behind the vulnerable route failed to check the swapExtraData parameter, letting the attacker embed a transferFrom call that moved previously approved assets out of victims' wallets and into the attacker's own contract.
As Beosin explained, the code failed to account for a scenario where the caller supplied zero WETH — which allowed the caller to specify arbitrary other function calls while still clearing the balance check.
Attacker's address: 0x50df5a2217588772471b84adbbe4194a2ed39066
SocketGateway contract: 0x3a23f943181408eac424116af7b7790c94cb97a5
Socket's contracts had previously been audited by both Peckshield and Consensys Diligence, but because the flawed route was introduced only three days before the exploit, it fell outside the scope of both prior reviews.
Assets Lost and an Extortion Attempt
The stolen funds — a mix of ETH, MATIC, WBTC, WETH, and DAI — totaled approximately $3.3 million. All of it remains sitting in the attacker's wallet, which subsequently received an on-chain message threatening to expose the attacker's identity unless paid: "100 ETH and I'll throw away the timing analysis routing through FixedFloat that doxxes you. After 6 hours I go to Zach. Act swiftly."

The Approvals Problem, Again
This incident once again highlights the risk of standing token approvals. Bungee has stated that it does not request infinite approvals by default, but any protocol that routes transactions through the affected contract needs to prioritize security considerations ahead of interface convenience — otherwise it becomes difficult to explain why so many users ended up exposed.
The single largest individual loss exceeded $600,000, and the five worst-affected wallets each lost more than $100,000 — a costly reminder of the importance of regularly managing token approvals. Approvals left unrevoked remain a standing liability for as long as the underlying contract is active (or even simply forgotten), and because tokens can be pulled directly from a wallet, a user doesn't need any deposited funds in the bridge itself to be affected.
Ultimately, the incident could have been avoided entirely had the team not pushed an unaudited, higher-risk change to a bridge contract already in production use.
Get new scam files the moment we publish them — usually 2–3 emails a week.