FENGSHOU Token Hack

REPORTED LOSS $191K
Low Access Control bsc

What happened

On April 24th, FENGSHOU (NGFS)  was exploited. $191k was gained as an attacker's profit.

The FENGSHOU (NGFS) token contract has an access control vulnerability in the delegateCallReserves function, which allowed a malicious actor to change the UniSwapV2 proxy address. This created an opportunity for the exploit, resulting in the actor earning approximately $191,000 in USDT tokens.

Attacker:

https://bscscan.com/address/0xd03d360d…6754a0

Attacker contract:

https://bscscan.com/address/0xc7378110…d035e4

Exploit tx:

https://bscscan.com/tx/0x8ff764dd…54de25

Case & protocol details

Classification Token / Access Control
Protocol Type Exploit/Access control
Implementation language Solidity

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.