logo

FEG Bridge Exploit Technical Analysis

ID: a8ba3431-6c1e-501d-84fa-0174e6efe226

STIX ID: report--a8ba3431-6c1e-501d-84fa-0174e6efe226

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2024-12-30

Date Updated: 2026-06-11

...
...

On 2024-12-29 an attacker exploited a flaw in the FEG bridge relayer's cross-chain message verification to add a malicious contract to the relayer whitelist and register unauthorized withdrawals, stealing approximately $1M in FEG tokens across Ethereum, Base, and BSC before converting funds to native tokens and sending them to Tornado Cash. The issue stems from the relayer accepting bridged messages that set whitelist entries when the message payload specifies the admin user, enabling bypass of intended admin checks; the relayer contract is unverified and analysis is based on decompiled code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.