logo

Revisiting FEI Protocol Incident

ID: 3b690a17-0a10-50dc-8c06-2e5551ad9ce5

STIX ID: report--3b690a17-0a10-50dc-8c06-2e5551ad9ce5

Feed Name: CertiK Blog

Threat Score
90/100

Date Published: 2022-06-27

Date Updated: 2026-06-11

...
...

On 30 April 2022 a re-entrancy exploit against Rari Fuse pools (after Fei/Rari merger) allowed an attacker to drain roughly $80M by flash-loaning assets, depositing collateral into a vulnerable forked Compound-style contract, invoking borrow() which transferred ETH before updating borrow state, then re-entering to call exitMarket() and withdraw collateral; the report includes transaction addresses, asset tallies, and a code-level explanation showing the check-effect-interaction violation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.