{"investigation":{"slug":"bungee","entity_name":"Bungee","trust_score":42,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Bungee Exchange is a cross-chain bridge aggregator and liquidity routing protocol developed by Socket (formerly SocketDotTech), founded in 2021 by Vaibhav Chellani and Rishabh Khurana. On January 16, 2024, the underlying Socket infrastructure was exploited via an inadequately validated smart contract route, resulting in approximately $3.3 million stolen from roughly 700 wallets with infinite token approvals. The protocol recovered approximately $2.23 million of the stolen funds one week later and resumed operations; it remains active as of 2026.","sections":[{"content":"Bungee Exchange is the consumer-facing cross-chain swap and bridging interface built on top of Socket Protocol, a chain-abstraction infrastructure layer. It enables users to bridge tokens and swap assets across more than 20 EVM-compatible blockchains. Socket was founded in 2021 by Vaibhav Chellani (CEO) and Rishabh Khurana (Co-Founder), who previously contributed to infrastructure at Biconomy. The protocol is integrated by platforms including MetaMask, Coinbase, OpenSea, Synthetix, and Polymarket, and has reported over $20 billion in total bridging volume across more than 4 million unique addresses. Investors include Coinbase Ventures, Lightspeed Venture Partners, Framework Ventures, Nascent, and others.","heading":"Overview","sources":[{"url":"https://docs.bungee.exchange/overview/what-is-bungee","name":"docs.bungee.exchange","type":"other","credibility":3},{"url":"https://theorg.com/org/socket-tech/org-chart/vaibhav-chellani","name":"theorg.com","type":"other","credibility":3},{"url":"https://www.crunchbase.com/person/vaibhav-chellani-b154","name":"crunchbase.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 16, 2024, Socket's SocketGateway smart contract was exploited, resulting in approximately $3.3 million in user funds being drained. The attack affected wallets that had previously granted infinite token approvals to Socket contracts. The exploit was first flagged publicly by security researcher @speekaway at approximately 18:20 UTC; PeckShield reported the incident at approximately 14:26 ET, and Socket confirmed the breach roughly 30 minutes later. The root cause was identified as incomplete validation of user input: a new bridging route deployed by Socket's admin three days prior to the exploit contained a performAction function that made unvalidated use of .call() with external user-supplied calldata (swapExtraData). This allowed an attacker to inject a transferFrom call and drain tokens pre-approved to the SocketGateway contract by victims. Assets stolen included ETH, MATIC, WBTC, WETH, and DAI. Approximately 700 wallets were affected; the largest individual loss was approximately $657,000, and 121 wallets each lost more than $10,000. Socket paused all affected contracts upon discovery. Security firm CertiK confirmed the vulnerability was analogous to exploit patterns previously seen on Dexible and Hector Bridge.","heading":"January 2024 Exploit — $3.3 Million Stolen","sources":[{"url":"https://www.coindesk.com/tech/2024/01/17/socket-bungee-restart-operations-after-apparent-33m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/272986/socket-says-bungee-protocol-exploited","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=socket-service-and-its-bungee-bridge-suffer-3-3-million-theft","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/socket-tech-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/socket","name":"revoke.cash","type":"other","credibility":3}],"severity":"medium"},{"content":"Bungee Exchange publicly stated that its own frontend and bridging interface were not directly responsible for the exploit, asserting that Bungee does not request infinite token approvals by default — the approval pattern that enabled the attack. Socket confirmed the vulnerability was in the underlying SocketGateway contract rather than in Bungee-specific code. Bungee paused the affected Socket route but maintained that other bridging functionality remained safe. Critics have noted that the distinction between Bungee and Socket is primarily one of branding, as both share the same smart contract infrastructure and the Bungee interface routes transactions through the vulnerable SocketGateway. The FXStreet reporting noted that research by IntoTheBlock showed the majority of DeFi exploits involve unaudited code, though neither source confirmed definitively whether the specific vulnerable route had received a third-party security audit prior to deployment.","heading":"Bungee's Claimed Isolation From the Exploit","sources":[{"url":"https://www.fxstreet.com/cryptocurrencies/news/breaking-bungee-exchange-and-socketdottech-likely-exploited-users-asked-to-revoke-address-202401161936","name":"fxstreet.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2024/01/17/socket-bungee-restart-operations-after-apparent-33m-exploit","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 23, 2024, Socket announced recovery of 1,032 ETH (approximately $2.23 million at then-current prices) from the stolen funds. The protocol stated it was developing a compensation plan for affected users, which would require victims to sign an on-chain message to prove wallet ownership; recipients would not need to grant additional approvals to claim reimbursement. Blockworks reported that Socket committed to making affected users 'whole.' The net unrecovered loss at time of reporting was approximately $1.07 million. No subsequent public confirmation of full disbursement has been located in available sources.","heading":"Fund Recovery and Victim Compensation","sources":[{"url":"https://www.coinlive.com/news-flash/425843","name":"coinlive.com","type":"other","credibility":3},{"url":"https://blockworks.co/news/defi-exploit-socket-compensation-plan","name":"blockworks.co","type":"other","credibility":3},{"url":"https://www.theblock.co/post/273964/socket-ether-recovery-bungee-exploit","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"The January 2024 exploit arose from a route added to the SocketGateway contract three days before the attack, without adequate input validation on the swapExtraData parameter. CertiK's post-incident analysis identified the vulnerability as 'unvalidated and direct use of .call() with external user-provided data,' enabling arbitrary function execution. No evidence has been found in available sources that the vulnerable route underwent a formal third-party security audit before deployment. The exploit pattern — deploying new contract routes without audit and with overprivileged approval scopes — is categorized as a critical operational security failure. Revoke.cash documented the incident and recommended users revoke any remaining approvals to Socket contracts.","heading":"Smart Contract Security Practices","sources":[{"url":"https://www.certik.com/resources/blog/socket-tech-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/socket","name":"revoke.cash","type":"other","credibility":3},{"url":"https://rivanorth.com/blog/hack-explained-socket","name":"rivanorth.com","type":"other","credibility":3}],"severity":"medium"},{"content":"AVOID.NET's intake data records Bungee as having been flagged by ZachXBT. Based on available public sources, ZachXBT did not author the primary exploit discovery report for the January 2024 incident — that credit belongs to security researcher @speekaway and PeckShield. It is possible ZachXBT amplified warnings about the exploit on his Telegram channel or X account at the time, which is consistent with his documented practice of broadcasting active exploits. No specific ZachXBT post or thread directly naming Bungee has been independently verified through public search results available to this investigation. The flag is noted as low-confidence pending identification of the specific ZachXBT statement.","heading":"ZachXBT Flag","sources":[{"url":"https://beincrypto.com/multi-chain-crypto-wallet-drain-phishing-exploit/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of April 2026, Bungee Exchange and its associated services (web app, exchange interface, API) are reported as operational according to the protocol's own status page. The platform is pursuing a Bungee Waitlist retroactive rewards campaign. No regulatory enforcement actions by the SEC, CFTC, or DOJ against Bungee or Socket have been identified in available sources. The protocol continues to operate across 20+ blockchains and claims over $20 billion in cumulative bridging volume.","heading":"Current Status","sources":[{"url":"https://status.bungee.exchange/","name":"status.bungee.exchange","type":"other","credibility":3},{"url":"https://www.bungee.exchange/","name":"bungee.exchange","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021","event":"Socket Protocol founded by Vaibhav Chellani and Rishabh Khurana, previously from Biconomy.","source":"","date_original":"2021-01-01"},{"date":"2022","event":"Socket raises seed/pre-seed funding from Coinbase Ventures, Lightspeed Venture Partners, Framework Ventures, Nascent, and others, reportedly totalling $5–12 million across rounds.","source":"","date_original":"2022-01-01"},{"date":"2024-01-13","event":"Socket admin deploys a new bridging route to the SocketGateway contract containing an unvalidated .call() vulnerability.","source":""},{"date":"2024-01-16","event":"Exploit executed: attacker drains approximately $3.3 million from ~700 wallets with infinite token approvals to SocketGateway. @speekaway first flags attack at 18:20 UTC; PeckShield reports at 14:26 ET; Socket confirms and pauses contracts.","source":""},{"date":"2024-01-17","event":"Socket and Bungee restart bridging operations after patching the vulnerable route. Compensation plan for victims announced.","source":""},{"date":"2024-01-23","event":"Socket announces recovery of 1,032 ETH (~$2.23 million) of stolen funds; victim claim process initiated via on-chain message signing.","source":""},{"date":"2024","event":"CertiK publishes post-incident technical analysis confirming incomplete input validation as root cause.","source":"","date_original":"2024-01-01"},{"date":"2026-04-27","event":"Bungee Exchange reports all services fully operational per its public status page.","source":""}],"sources_used":[{"url":"https://docs.bungee.exchange/overview/what-is-bungee","name":"docs.bungee.exchange","type":"other","archive_url":"http://web.archive.org/web/20260417155726/https://docs.bungee.exchange/overview/what-is-bungee","credibility":3,"archive_timestamp":"2026-04-17T15:57:26+00:00"},{"url":"https://theorg.com/org/socket-tech/org-chart/vaibhav-chellani","name":"theorg.com","type":"other","archive_url":"https://web.archive.org/web/20260829142908/https://theorg.com/org/socket-tech?p=vaibhav-chellani","credibility":3,"archive_timestamp":"2026-08-29T14:29:08+00:00"},{"url":"https://www.crunchbase.com/person/vaibhav-chellani-b154","name":"crunchbase.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.coindesk.com/tech/2024/01/17/socket-bungee-restart-operations-after-apparent-33m-exploit","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260420153633/https://www.coindesk.com/tech/2024/01/17/socket-bungee-restart-operations-after-apparent-33m-exploit","credibility":3,"archive_timestamp":"2026-04-20T15:36:33+00:00"},{"url":"https://www.theblock.co/post/272986/socket-says-bungee-protocol-exploited","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.web3isgoinggreat.com/?id=socket-service-and-its-bungee-bridge-suffer-3-3-million-theft","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260413113309/https://www.web3isgoinggreat.com/?id=socket-service-and-its-bungee-bridge-suffer-3-3-million-theft","credibility":3,"archive_timestamp":"2026-04-13T11:33:09+00:00"},{"url":"https://www.certik.com/resources/blog/socket-tech-incident-analysis","name":"certik.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://revoke.cash/exploits/socket","name":"revoke.cash","type":"other","archive_url":"http://web.archive.org/web/20260517213847/https://revoke.cash/exploits/socket","credibility":3,"archive_timestamp":"2026-05-17T21:38:47+00:00"},{"url":"https://www.fxstreet.com/cryptocurrencies/news/breaking-bungee-exchange-and-socketdottech-likely-exploited-users-asked-to-revoke-address-202401161936","name":"fxstreet.com","type":"other","archive_url":"https://web.archive.org/web/20260830050403/https://www.fxstreet.com/cryptocurrencies/news/breaking-bungee-exchange-and-socketdottech-likely-exploited-users-asked-to-revoke-address-202401161936","credibility":3,"archive_timestamp":"2026-08-30T05:04:03+00:00"},{"url":"https://www.coinlive.com/news-flash/425843","name":"coinlive.com","type":"other","archive_url":"https://web.archive.org/web/20260830004708/https://www.coinlive.com/news-flash/425843","credibility":3,"archive_timestamp":"2026-08-30T00:47:08+00:00"},{"url":"https://blockworks.co/news/defi-exploit-socket-compensation-plan","name":"blockworks.co","type":"other","archive_url":"http://web.archive.org/web/20251128150645/https://blockworks.co/news/defi-exploit-socket-compensation-plan","credibility":3,"archive_timestamp":"2025-11-28T15:06:45+00:00"},{"url":"https://www.theblock.co/post/273964/socket-ether-recovery-bungee-exploit","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260726045228/https://www.theblock.co/post/273964/socket-ether-recovery-bungee-exploit","credibility":3,"archive_timestamp":"2026-07-26T04:52:28+00:00"},{"url":"https://rivanorth.com/blog/hack-explained-socket","name":"rivanorth.com","type":"other","archive_url":"http://web.archive.org/web/20260311201713/https://rivanorth.com/blog/hack-explained-socket","credibility":3,"archive_timestamp":"2026-03-11T20:17:13+00:00"},{"url":"https://beincrypto.com/multi-chain-crypto-wallet-drain-phishing-exploit/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260102120018/https://beincrypto.com/multi-chain-crypto-wallet-drain-phishing-exploit/","credibility":3,"archive_timestamp":"2026-01-02T12:00:18+00:00"},{"url":"https://status.bungee.exchange/","name":"status.bungee.exchange","type":"other","archive_url":"http://web.archive.org/web/20260521082828/https://status.bungee.exchange/","credibility":3,"archive_timestamp":"2026-05-21T08:28:28+00:00"},{"url":"https://www.bungee.exchange/","name":"bungee.exchange","type":"other","archive_url":"http://web.archive.org/web/20260827183235/https://www.bungee.exchange/","credibility":3,"archive_timestamp":"2026-08-27T18:32:35+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:35.758308+00:00","updated_at":"2026-08-30T05:14:08.649807+00:00"}}