FPR Hack

Reported loss $29K
BNB Chain
Improper Access Control

What happened

On 14 December 2022 an attacker took about $29,000 from contracts tied to the FPR token on BNB Chain. Four contracts holding FPR and FPR/BSC-USD liquidity tokens exposed a public setAdmin() function, so anyone could make themselves admin and then pull out the contracts' balances. The attacker sold the FPR for USDT and removed the liquidity.

PeckShield reported that FPR fell about 95% and that around 101 BNB had been sent to Tornado Cash.

How it happened

  1. The attacker called setAdmin() on each of four victim contracts, making the attack contract the admin. The function had no access check.
  2. On three of them, the attacker called the admin-only remaining() function to transfer the contract's FPR balance out, then sold that FPR for USDT on PancakeSwap after each withdrawal.
  3. On the fourth, the same call withdrew the FPR/BSC-USD LP tokens, which the attacker redeemed with removeLiquidity() before selling the FPR half for USDT.
  4. The proceeds, reported at about $29,000, were partly moved to Tornado Cash.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.