FEG token became the latest flash loan victim as Peck Shield steps in to secure stolen funds.
Flash Loan Attack
Feed Every Gorilla (FEG) suffered two flash loan attacks causing losses of approximately $1.9 million as efforts are taken to recover the stolen funds.
In a tweet by the FEG team, the community was informed of an attack that took place on May 15. Barely eight hours after the announcement, another attack took place, resulting in further losses. The first exploit through BNB Chain managed to drain approximately $1.3 million, involving $FEG, $fBNB, and $R0X (FEGrox). https://platform.twitter.com/embed/Tweet.html?dnt=false&embedId=twitter-widget-0&features=eyJ0ZndfZXhwZXJpbWVudHNfY29va2llX2V4cGlyYXRpb24iOnsiYnVja2V0IjoxMjA5NjAwLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X3NlbnNpdGl2ZV9tZWRpYV9pbnRlcnN0aXRpYWxfMTM5NjMiOnsiYnVja2V0IjoiaW50ZXJzdGl0aWFsIiwidmVyc2lvbiI6bnVsbH0sInRmd190d2VldF9yZXN1bHRfbWlncmF0aW9uXzEzOTc5Ijp7ImJ1Y2tldCI6InR3ZWV0X3Jlc3VsdCIsInZlcnNpb24iOm51bGx9fQ%3D%3D&frame=false&hideCard=false&hideThread=false&id=1526114462717059073&lang=en&origin=https%3A%2F%2Fwww.bsc.news%2Fpost%2Ffeg-token-endures-exploit-peck-shield-supports-aftermath&sessionId=edaf83a7690f454eae72ab7da383907487fabfe0&theme=light&widgetsVersion=c8fe9736dd6fb%3A1649830956492&width=550px
The attacker transferred the stolen funds through Tornado Cash, a mixer that can obfuscate digital trails. An attack on FEG’s Ethereum smart contract also caused a loss of about $590,000, bringing total losses of up to $1.9 million in assets.

As the attacker used Tornado Cash to hide its tracks, efforts are being made to retrieve the stolen funds.
How has FEG Been Exploited?
Certik Alert detailed how the attack took place in the followingTwitter thread. https://platform.twitter.com/embed/Tweet.html?dnt=false&embedId=twitter-widget-1&features=eyJ0ZndfZXhwZXJpbWVudHNfY29va2llX2V4cGlyYXRpb24iOnsiYnVja2V0IjoxMjA5NjAwLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X3NlbnNpdGl2ZV9tZWRpYV9pbnRlcnN0aXRpYWxfMTM5NjMiOnsiYnVja2V0IjoiaW50ZXJzdGl0aWFsIiwidmVyc2lvbiI6bnVsbH0sInRmd190d2VldF9yZXN1bHRfbWlncmF0aW9uXzEzOTc5Ijp7ImJ1Y2tldCI6InR3ZWV0X3Jlc3VsdCIsInZlcnNpb24iOm51bGx9fQ%3D%3D&frame=false&hideCard=false&hideThread=false&id=1526374224730140673&lang=en&origin=https%3A%2F%2Fwww.bsc.news%2Fpost%2Ffeg-token-endures-exploit-peck-shield-supports-aftermath&sessionId=edaf83a7690f454eae72ab7da383907487fabfe0&theme=light&widgetsVersion=c8fe9736dd6fb%3A1649830956492&width=550px
The attack was carried out through interactions with unverified contracts. This exploitation was done using the Swap-to-Swap (S2S) functionality within the FEG token swap contracts on BNB Chain and the ETH network. The only point of attack was the Swap-to-Swap functionality, which always sends funds from one contract to another. The team announced that this function has been removed, and new layers of security have been added.
Trading on FEG and FEGex was temporarily halted after the team got notification of unusual activities. Trading on PancakeSwap and Uniswap continued without any issues. The FEG Development team is working on updating the swap contracts, and the Swap-to-Swap (S2S) functionality is removed as a precaution after consulting PeckShield.
What is Feed Every Gorilla:
FEG explains the main idea behind its token is to provide a decentralized transaction network that operates on the Ethereum blockchain and the BNB Chain. A hyper-deflationary token, FEG has a maximum circulating supply of 100 quadrillions on both the aforementioned chains, which also includes an inaccessible burn wallet. A 2% transaction tax is distributed among all holders based on the percentage of ownership, including the burn wallet which acts as a holder that collects tokens over a period in which transactions occur. The team is keen to stress that there is no burn limit, and with this being the case, users will get to enjoy a ‘never-ending cycle of passive income with positive price pressure.’
Where to Find FEG:
Source : bsc.news