FEG (Feed Every Gorilla) Hack
What happened
On 30th December 2024, FEGtoken (@FEGtoken) was exploited on Ethereum, Binance Smart Chain (BSC), and Base, resulting in total losses exceeding $900,000.
Because the relayer contract did not confirm the legitimacy of the source address for bridge messages, the attacker sent a spoofed payload from Base, convincing the relayer that the withdrawal request was valid. The relayer then approved large sums of FEG tokens for withdrawal on BSC, which the attacker quickly redeemed for profit. The three primary transactions illustrate the progression of the hack: first, the attacker submitted a malicious Wormhole payload from Base; next, the relayer incorrectly authorized token withdrawals on BSC; finally, the attacker withdrew the tokens and monetized them.
This incident underscores the importance of strict source validation in cross-chain relayer contracts.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.