Incident case

SOCKET 2024 Gateway approval exploit

An attacker used an incomplete input-validation path in the Socket Gateway contract to drain assets from Ethereum wallets that had granted approvals to the affected route. SOCKET paused the contracts, removed the route, restored service, and later reported recovering 1,032 ETH.

reviewedcurrent

Incident facts

Incident title
SOCKET 2024 Gateway approval exploit
Bridge
SOCKET Protocol
Incident date
2024-01-16
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum
Affected assets
USDC, USDT, Unknown
Attack category
Cross Chain Contract Exploit
Reported loss
Approximately $3.3 million
Amount confidence
High
Loss amount basis
Independent Security Analysis Corroborated By Contemporaneous Reporting
Recovery
Partial Recovery
Reimbursement
Announced
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Partial
Resolution
Unresolved
Last reviewed
2026-06-15
Last verified
2026-06-15

Amount and valuation

Security analysis and contemporaneous reporting estimated approximately $3.3 million drained from approved wallets.

The recovered 1,032 ETH is tracked separately and is not subtracted from the incident amount field.

Why this remains unresolved

Timeline events

  • SOCKET paused affected contracts after approval exploit2024-01-16

    SOCKET reported an incident affecting wallets with approvals to the vulnerable route and paused the affected contracts while investigating and removing the route.

    Exploit Detected And Contracts PausedHigh
  • SOCKET restored service after removing the vulnerable route2024-01-17

    SOCKET said the affected route had been disabled and normal bridging activity was restored after the incident response.

    Bridge ReopenedHigh

    Event type normalized from legacy descriptive value service_restored.

  • SOCKET reported recovery of 1,032 ETH2024-01-23

    SOCKET reported recovering 1,032 ETH connected to the January 16 incident and said a recovery and distribution plan would follow.

    Funds RecoveredHigh

    The recovery amount is not treated as proof of final user distribution.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.