FEG (Feed Every Gorilla) Hack

TOTAL LOST $900K
Low Other

What happened

On 30th December 2024, FEGtoken (@FEGtoken) was exploited on Ethereum, Binance Smart Chain (BSC), and Base, resulting in total losses exceeding $900,000.

Because the relayer contract did not confirm the legitimacy of the source address for bridge messages, the attacker sent a spoofed payload from Base, convincing the relayer that the withdrawal request was valid. The relayer then approved large sums of FEG tokens for withdrawal on BSC, which the attacker quickly redeemed for profit. The three primary transactions illustrate the progression of the hack: first, the attacker submitted a malicious Wormhole payload from Base; next, the relayer incorrectly authorized token withdrawals on BSC; finally, the attacker withdrew the tokens and monetized them.

This incident underscores the importance of strict source validation in cross-chain relayer contracts.

Case & protocol details

Classification Other
Protocol Type Exploit/Other
Official Website feg.io/
Protocol Twitter/X @FEGtoken

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.