FPR Hack
What happened
On 14 December 2022 an attacker took about $29,000 from contracts tied to the FPR token on BNB Chain. Four contracts holding FPR and FPR/BSC-USD liquidity tokens exposed a public setAdmin() function, so anyone could make themselves admin and then pull out the contracts' balances. The attacker sold the FPR for USDT and removed the liquidity.
PeckShield reported that FPR fell about 95% and that around 101 BNB had been sent to Tornado Cash.
How it happened
- The attacker called
setAdmin()on each of four victim contracts, making the attack contract the admin. The function had no access check. - On three of them, the attacker called the admin-only
remaining()function to transfer the contract's FPR balance out, then sold that FPR for USDT on PancakeSwap after each withdrawal. - On the fourth, the same call withdrew the FPR/BSC-USD LP tokens, which the attacker redeemed with
removeLiquidity()before selling the FPR half for USDT. - The proceeds, reported at about $29,000, were partly moved to Tornado Cash.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.