Forest Tiger Pro Hack
Incident Overview
The Forest Tiger Pro project has been rugpulled by the token creator, resulting in $700k of ill-gotten funds.
The creator of the token deployed the token on the BSC network, where 21M $TIGER was minted in total and 500k tokens of the total supply was minted to the scammer address (B). The token creator made a series of transactions where all tokens from his balance were sent to three staking contracts and two exchange contracts:
1) https://bscscan.com/tx/0xf28bd3d5…75691b
2) https://bscscan.com/tx/0xf1e106bc…c4ed9b
3) https://bscscan.com/tx/0x20cf8df3…b44e9d
4) https://bscscan.com/tx/0x284bc017…32df81
5) https://bscscan.com/tx/0x722e161e…0f1bdd
The scammer address (B, which held 500k tokens sent 35k tokens to scammer address (C), then an hour later another 150k were sent:
1) https://bscscan.com/tx/0x10fe4704…5af0e8
2) https://bscscan.com/tx/0xe6744c64…d89df6
The scammer address (B) added liquidity to the TIGER/USDT pair for 2.6M $USDT in these 3 transactions:
1) https://bscscan.com/tx/0x1465e26a…325504
2) https://bscscan.com/tx/0x15f761f3…c00a70
3) https://bscscan.com/tx/0xcca2ebf3…7c458f
The scammer address (C) added liquidity to the
TIGER/USDT pair for 1M $USDT and approximately 39k $TIGER:
https://bscscan.com/tx/0x7dc35d4f…bf5a58
Then he proceeded to gradually raise the price of the token by making exchanges for 8.7k on average $USDT, investing a total of $55k. Below some example transactions:
1) https://bscscan.com/tx/0x76c9c19a…cc14e0
2) https://bscscan.com/tx/0x179f31f3…b71d8e
3) https://bscscan.com/tx/0x00ea3681…edd652
On July 13, scammer address (C) removed the liquidity with a profit of 500k $USDT:
https://bscscan.com/tx/0xd72bdfc1…39cff5
Then the scammer address (B) also removed the liquidity with permission: https://bscscan.com/tx/0xc03899a5…539d93
All the USDT were transferred to scammer address (D):
1) https://bscscan.com/tx/0x8de16393…d9b84f
2) https://bscscan.com/tx/0x96248173…9b817a
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Forest Tiger Pro, these are the critical security checks that could have prevented this incident (July 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Forest Tiger Pro
The Forest Tiger Pro hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.