Shield: The fundamental cause of the FEG attack is the composability issue that arose when integrating with the Wormhole bridge

Odaily Planet Daily News: PardShield stated that it analyzed the latest FEG Hacker attack incident, and the fundamental reason seems to be the composability issue that occurred when integrating the underlying Wormhole bridge for Cross-Chain Interaction messages/Token transfers. Specifically, Hacker created a false deposit message (not supported by the audited FEG SmartBridge through an unexpected Wormhole relay interface), and then transmitted it to another chain and received by the FEG SmartBridge (now disabled) to extract FEG Token. Please note that the SmartDeFi code was not affected.

Meanwhile, the Wormhole Foundation stated: "The FEG security incident has nothing to do with Wormhole. All Wormhole contracts are completely unaffected and have nothing to do with this issue." Earlier news, FEG suspected to have suffered an attack and lost about 1 million dollars.

View Original
  • Reward
  • 4
  • Share
Comment
0/400
No comments