{"investigation":{"slug":"fegex","entity_name":"FEGex","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"FEGex is a decentralized exchange (DEX) and DeFi launchpad built around the FEG (Feed Every Gorilla) token ecosystem, operating on Ethereum and BNB Chain. The protocol has suffered three separate security exploits between 2022 and 2024, resulting in cumulative losses exceeding $3.6 million and a near-total collapse of token value following the most recent incident. The team operates anonymously and the protocol has demonstrated a repeated inability to prevent critical smart contract vulnerabilities despite multiple third-party audits.","sections":[{"content":"FEGex launched as a decentralized exchange protocol associated with the FEG (Feed Every Gorilla) token, initially deployed on both Ethereum and BNB Chain (BSC). The protocol offered a proprietary swap mechanism called FEGexPRO and later expanded to include a launchpad service branded SmartDeFi, which allowed third-party token projects to deploy asset-backed tokens with liquidity locking features. The team behind FEGex operates anonymously; the primary developer is known by the pseudonym 'FEGrox' or '@lifeisdefi' on social media. According to community sources, the project was founded approximately five years prior to 2026, and at its peak comprised 19 administrators and nearly 30 social media moderators, with observers noting the team contained more marketing personnel than engineers. FEGex processed peer-to-peer non-custodial swaps and hosted more than 100 third-party SmartDeFi token projects within its liquidity ecosystem at various points during 2021-2022.","heading":"Protocol Overview","sources":[{"url":"https://ambcrypto.com/making-defi-mainstream-an-interview-with-fegex-marketing-manager-chris/","name":"ambcrypto.com","type":"other","credibility":3},{"url":"https://feg.io/","name":"feg.io","type":"other","credibility":3},{"url":"https://docs.feg.io/smartdefi-tm-platform/smartdefi-protocol","name":"docs.feg.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On May 15, 2022 at approximately 20:22 UTC, the FEGexPRO smart contracts on both Ethereum and BNB Chain were exploited via a flash loan attack, resulting in a loss of approximately $1.3 million in combined assets (approximately 3,280 BNB and 144 ETH). Security firms BlockSec and CertiK independently analyzed the attack and identified two core vulnerabilities: an arbitrary approval flaw caused by an unvalidated 'path' parameter in the swapToSwap() function, and an accounting inconsistency between actual contract balances and internally recorded values. The attacker obtained flash loan capital, deposited funds to inflate internal balance records via depositInternal(), then called swapToSwap() with attacker-controlled fake contract addresses, causing the FEGexPRO contract to grant unlimited spending approvals to 10 attacker-controlled addresses. This cycle was repeated systematically across 13 FEGexPRO contract instances to drain approximately 114 fBNB per address. Stolen funds were subsequently laundered through Tornado Cash within days of the attack. CertiK published a full technical postmortem on May 16, 2022. FEG announced a pause of trading and described the attack in a public tweet thread acknowledging the 'Swap-to-Swap exploit.'","heading":"May 2022 Flash Loan Exploit (Incident 1)","sources":[{"url":"https://certik.com/resources/blog/w6AxRmf6l2ow4zL884gr8-feg-token-flashloan-exploit-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://blocksecteam.medium.com/the-analysis-of-fegtoken-security-incident-devils-in-the-details-ea554f52bdcb","name":"blocksecteam.medium.com","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/beosins-detailed-analysis-of-fegtoken-flashloan-attack-3-280-bnb-and-144-eth-lost-758d972ac65b","name":"medium.com","type":"other","credibility":3},{"url":"https://x.com/FEGtoken/status/1527327080031330305","name":"x.com","type":"other","credibility":3},{"url":"https://certik.medium.com/20220516-feg-token-flashloan-exploit-analysis-4bfcd23bcfc9","name":"certik.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In October 2022, FEG suffered a second major loss as a result of an exploit targeting Team Finance, a third-party DeFi platform used to lock liquidity for SmartDeFi token projects. The vulnerability resided in Team Finance's Uniswap v2-to-v3 migration function, which allowed an attacker to manipulate the price of liquidity tokens during the migration process. Four FEG-associated liquidity locks were exploited, with losses to the FEG ecosystem estimated at approximately $950,000 to $2 million. Team Finance was drained of a total of $14.5 million across multiple projects in the same incident. In a notable outcome, the attacker subsequently returned approximately $1.9 million (reported as 548 ETH) to affected projects including FEG on or around October 30, 2022, recovering the majority of the FEG-associated losses. FEG Token's price rallied approximately 11% following confirmation of the fund recovery. This incident highlighted a systemic dependency risk: FEG's SmartDeFi ecosystem relied on a third-party contract that had itself not been hardened against migration-path manipulation.","heading":"October 2022 Team Finance Liquidity Lock Exploit (Incident 2)","sources":[{"url":"https://protos.com/feg-token-holders-in-despair-after-third-hack-causes-99-dump/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/feed-every-gorilla-hack-2","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://www.bsc.news/post/feg-token-rallies-after-recovery-of-funds-from-team-finance-exploit","name":"bsc.news","type":"other","credibility":3},{"url":"https://www.theblock.co/post/180369/hacker-uses-2700-to-drain-15-8-million-from-team-finance","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 29, 2024, FEG's cross-chain SmartBridge was exploited for approximately $1.3 million (96.3 ETH on Ethereum, 73.3 ETH on Base, and 712 BNB on BSC), marking the protocol's third significant security failure. The attacker exploited a critical flaw in FEG's relay contract: the relayer's whitelist could be updated via a bridged message, and the logic failed to validate whether the source address of an incoming Wormhole bridge message was authorized to trigger a withdrawal registration. The attacker added their own contract to the whitelist by spoofing an admin address, then sent a malicious message to set withdrawable token balances of approximately 45.7 billion FEG tokens, and withdrew those tokens without any corresponding deposits on the source chains. The extracted FEG tokens were immediately swapped for ETH and BNB, causing the FEG token price to collapse by approximately 99%. Stolen proceeds were transferred to Tornado Cash. Security firm CertiK confirmed the vulnerability was not inherent to the Wormhole protocol itself, but resided entirely within FEG's custom implementation layer. Halborn security firm corroborated this analysis, describing it as a 'composability issue' between SmartBridge and the underlying Wormhole integration. The SmartBridge contract had previously undergone a security audit, but the specific composability vulnerability was reportedly outside the audit's original scope. The team initially speculated publicly about a Wormhole-side vulnerability before correcting this assessment.","heading":"December 2024 SmartBridge Exploit (Incident 3)","sources":[{"url":"https://www.certik.com/resources/blog/feg-bridge-exploit-technical-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-feed-every-gorilla-feg-hack-december-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://protos.com/feg-token-holders-in-despair-after-third-hack-causes-99-dump/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.vibraniumaudits.com/post/feg-tokens-third-hack-in-december-2024-results-in-99-value-drop","name":"vibraniumaudits.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/academy/article/8c4f1c8b-b61c-4fae-9fc5-faa49e723d1b","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"FEG has engaged multiple third-party auditors over the project's lifespan, including PeckShield, SourceHat, and CertiK. PeckShield was retained as the primary auditor and produced reports covering FEG-SmartDeFi, FEG-Migrator, FEG-Staking, FEG-FeeConverter, and the core FEG token contract. Despite this audit coverage, the protocol was successfully exploited on three separate occasions. The May 2022 flash loan exploit targeted the swapToSwap() input validation — a vulnerability class (unsanitized user-controlled parameters) that is standard in smart contract audit checklists. The December 2024 SmartBridge exploit targeted composability between FEG's custom relay logic and the Wormhole protocol integration, an area the team acknowledged may not have been within the original audit scope. The pattern of repeated critical vulnerabilities following audits suggests either incomplete audit scope definition, insufficient remediation of audit findings, or the introduction of new attack surfaces through incremental contract updates without corresponding re-auditing. FEG's official documentation lists security audits at docs.feg.io/welcome/security-audits.","heading":"Audit History and Security Posture","sources":[{"url":"https://docs.feg.io/welcome/security-audits","name":"docs.feg.io","type":"other","credibility":3},{"url":"https://certik.medium.com/feg-token-flashloan-exploit-analysis-5006070aca2d","name":"certik.medium.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-feed-every-gorilla-feg-hack-december-2024","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the May 2022 exploit, FEG undertook a significant protocol restructuring. On February 22, 2023, the team launched a token migration, consolidating the legacy FEGeth and FEGbsc tokens — as well as the ROX companion token — into a unified new contract at a 1,000,000:1 ratio. The migration was accompanied by a 200 ETH liquidity loan to replenish the FEGbsc liquidity pool. The new token introduced staking with a 2% transaction tax on volume routed to stakers. FEG also published a recovery program (documented at docs.feg.io/recovery/old-fegex-sd-recovery) for holders of projects drained in the 2022 SmartDeFi exploit, describing a staged recovery process for over 100 affected projects. The team reported recovering over $2 million in user funds during the post-exploit remediation period. Despite these efforts, the December 2024 bridge exploit again devastated token value. As of early 2025, FEGex and the SmartBridge remain paused. The project's trajectory demonstrates a recurring cycle of exploit, restructuring, relaunch, and subsequent exploit.","heading":"Token Migration and Recovery Attempts","sources":[{"url":"https://docs.feg.io/recovery/old-fegex-sd-recovery","name":"docs.feg.io","type":"other","credibility":3},{"url":"https://www.bsc.news/post/feg-ready-for-migration-to-smart-defi-after-2nd-anniversary-launch-feb-22","name":"bsc.news","type":"other","credibility":3},{"url":"https://docs.feg.io/feg-smartdefi-tm/feg-upgrade","name":"docs.feg.io","type":"other","credibility":3},{"url":"https://protos.com/feg-token-holders-in-despair-after-third-hack-causes-99-dump/","name":"protos.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The FEGex team operates with a high degree of anonymity. The lead developer is publicly known only by the pseudonyms 'FEGrox' and '@lifeisdefi.' Other identified team members include a marketing manager named 'Chris,' who gave a public interview to AMBCrypto. No founders or core engineers have disclosed their legal identities. Community observers have noted that the project's team structure, at its peak, comprised substantially more marketing and social media personnel than engineers — approximately 19 administrators and nearly 30 moderators versus an unspecified small developer count. The Scam Detector platform rated fegtoken.com with a trust score of 27.5 out of 100, categorizing the site as 'Debatable' and 'Controversial' and flagging high-risk activity signals related to phishing and spamming. Anonymous team operation is a materially elevated risk factor in DeFi, as it removes personal accountability in the event of exploits, alleged negligence, or potential exit scenarios.","heading":"Team Anonymity and Transparency Concerns","sources":[{"url":"https://ambcrypto.com/making-defi-mainstream-an-interview-with-fegex-marketing-manager-chris/","name":"ambcrypto.com","type":"other","credibility":3},{"url":"https://www.scam-detector.com/validator/fegtoken-com-review/","name":"scam-detector.com","type":"other","credibility":3},{"url":"https://www.quora.com/Is-the-FEG-crypto-token-a-scam","name":"quora.com","type":"other","credibility":3},{"url":"https://fegrox.com/","name":"fegrox.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The on-chain investigator ZachXBT has flagged FEGex in the context of its security incidents and fund-flow analysis. ZachXBT is a pseudonymous blockchain forensics researcher known for documenting scams, exploits, and suspicious on-chain activity across the crypto ecosystem. The flagging is consistent with ZachXBT's standard practice of documenting projects with repeated security failures or patterns of harm to retail holders. The specific nature and content of ZachXBT's statements regarding FEGex have not been independently verified from a primary source in this investigation and should be treated as an attributed flag pending direct source confirmation.","heading":"ZachXBT Flagging","sources":[{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://twitter.com/zachxbt","name":"twitter.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021","event":"FEG (Feed Every Gorilla) token launches on Ethereum and BNB Chain; FEGex DEX and FEGexPRO swap contracts deployed.","source":"","date_original":"2021-01-01"},{"date":"2021-04-21","event":"Hotbit exchange lists FEG and FEGBSC tokens, broadening retail access.","source":""},{"date":"2022-05-15","event":"FEGexPRO contracts on Ethereum and BNB Chain exploited via flash loan attack targeting swapToSwap() input validation vulnerability; approximately $1.3 million (3,280 BNB + 144 ETH) stolen. Funds laundered via Tornado Cash.","source":""},{"date":"2022-05-16","event":"CertiK and BlockSec publish independent technical postmortems on the May 15 exploit.","source":""},{"date":"2022-10","event":"Team Finance, a liquidity lock platform used by FEG's SmartDeFi ecosystem, is exploited for $14.5 million total; FEG-associated losses estimated at approximately $950,000–$2 million.","source":"","date_original":"2022-10-01"},{"date":"2022-10-30","event":"Team Finance exploiter returns approximately $1.9 million to affected projects; FEG recovers approximately 548 ETH. FEG token price rallies ~11%.","source":""},{"date":"2023-02-22","event":"FEG token migrates to new SmartDeFi-based contract at a 1,000,000:1 ratio, consolidating FEGeth, FEGbsc, and ROX tokens. Protocol restructuring announced.","source":""},{"date":"2023-03-13","event":"FEG team secures a 200 ETH liquidity loan to replenish FEGbsc liquidity pool post-migration.","source":""},{"date":"2024-12-29","event":"FEG SmartBridge cross-chain contract exploited via Wormhole relay message spoofing vulnerability; approximately $1.3 million (96.3 ETH on ETH, 73.3 ETH on Base, 712 BNB on BSC) stolen. FEG token price collapses approximately 99%. Funds laundered via Tornado Cash.","source":""},{"date":"2024-12-30","event":"CertiK and Halborn publish technical analyses confirming the bridge exploit was caused by flawed access control in FEG's own relay contract, not in the Wormhole protocol itself.","source":""}],"sources_used":[{"url":"https://ambcrypto.com/making-defi-mainstream-an-interview-with-fegex-marketing-manager-chris/","name":"ambcrypto.com","type":"other","archive_url":"https://web.archive.org/web/20260829224523/https://ambcrypto.com/making-defi-mainstream-an-interview-with-fegex-marketing-manager-chris/","credibility":3,"archive_timestamp":"2026-08-29T22:45:23+00:00"},{"url":"https://feg.io/","name":"feg.io","type":"other","archive_url":"http://web.archive.org/web/20260608022519/https://feg.io/","credibility":3,"archive_timestamp":"2026-06-08T02:25:19+00:00"},{"url":"https://docs.feg.io/smartdefi-tm-platform/smartdefi-protocol","name":"docs.feg.io","type":"other","archive_url":"http://web.archive.org/web/20260616074339/https://docs.feg.io/smartdefi-tm-platform/smartdefi-protocol","credibility":3,"archive_timestamp":"2026-06-16T07:43:39+00:00"},{"url":"https://certik.com/resources/blog/w6AxRmf6l2ow4zL884gr8-feg-token-flashloan-exploit-analysis","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260829073841/https://www.certik.com/blog/w6AxRmf6l2ow4zL884gr8-feg-token-flashloan-exploit-analysis","credibility":3,"archive_timestamp":"2026-08-29T07:38:41+00:00"},{"url":"https://blocksecteam.medium.com/the-analysis-of-fegtoken-security-incident-devils-in-the-details-ea554f52bdcb","name":"blocksecteam.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/coinmonks/beosins-detailed-analysis-of-fegtoken-flashloan-attack-3-280-bnb-and-144-eth-lost-758d972ac65b","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://x.com/FEGtoken/status/1527327080031330305","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://certik.medium.com/20220516-feg-token-flashloan-exploit-analysis-4bfcd23bcfc9","name":"certik.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251114114647/https://certik.medium.com/20220516-feg-token-flashloan-exploit-analysis-4bfcd23bcfc9","credibility":3,"archive_timestamp":"2025-11-14T11:46:47+00:00"},{"url":"https://protos.com/feg-token-holders-in-despair-after-third-hack-causes-99-dump/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260612053837/https://protos.com/feg-token-holders-in-despair-after-third-hack-causes-99-dump/","credibility":3,"archive_timestamp":"2026-06-12T05:38:37+00:00"},{"url":"https://www.web3isgoinggreat.com/single/feed-every-gorilla-hack-2","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260211023126/https://www.web3isgoinggreat.com/single/feed-every-gorilla-hack-2","credibility":3,"archive_timestamp":"2026-02-11T02:31:26+00:00"},{"url":"https://www.bsc.news/post/feg-token-rallies-after-recovery-of-funds-from-team-finance-exploit","name":"bsc.news","type":"other","archive_url":"https://web.archive.org/web/20260829083930/https://bsc.news/post/what-is-bnb-chain-layer-one-blockchain-guide","credibility":3,"archive_timestamp":"2026-08-29T08:39:30+00:00"},{"url":"https://www.theblock.co/post/180369/hacker-uses-2700-to-drain-15-8-million-from-team-finance","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.certik.com/resources/blog/feg-bridge-exploit-technical-analysis","name":"certik.com","type":"other","archive_url":"http://web.archive.org/web/20251019065255/https://www.certik.com/resources/blog/feg-bridge-exploit-technical-analysis","credibility":3,"archive_timestamp":"2025-10-19T06:52:55+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-feed-every-gorilla-feg-hack-december-2024","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260414124259/https://www.halborn.com/blog/post/explained-the-feed-every-gorilla-feg-hack-december-2024","credibility":3,"archive_timestamp":"2026-04-14T12:42:59+00:00"},{"url":"https://www.vibraniumaudits.com/post/feg-tokens-third-hack-in-december-2024-results-in-99-value-drop","name":"vibraniumaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260609111610/https://vibraniumaudits.com/post/feg-tokens-third-hack-in-december-2024-results-in-99-value-drop","credibility":3,"archive_timestamp":"2026-06-09T11:16:10+00:00"},{"url":"https://coinmarketcap.com/academy/article/8c4f1c8b-b61c-4fae-9fc5-faa49e723d1b","name":"coinmarketcap.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.feg.io/welcome/security-audits","name":"docs.feg.io","type":"other","archive_url":"http://web.archive.org/web/20260610065352/https://docs.feg.io/welcome/security-audits","credibility":3,"archive_timestamp":"2026-06-10T06:53:52+00:00"},{"url":"https://certik.medium.com/feg-token-flashloan-exploit-analysis-5006070aca2d","name":"certik.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.feg.io/recovery/old-fegex-sd-recovery","name":"docs.feg.io","type":"other","archive_url":"http://web.archive.org/web/20260312222147/https://docs.feg.io/recovery/old-fegex-sd-recovery","credibility":3,"archive_timestamp":"2026-03-12T22:21:47+00:00"},{"url":"https://www.bsc.news/post/feg-ready-for-migration-to-smart-defi-after-2nd-anniversary-launch-feb-22","name":"bsc.news","type":"other","archive_url":"https://web.archive.org/web/20260829084002/https://bsc.news/post/what-is-bnb-chain-layer-one-blockchain-guide","credibility":3,"archive_timestamp":"2026-08-29T08:40:02+00:00"},{"url":"https://docs.feg.io/feg-smartdefi-tm/feg-upgrade","name":"docs.feg.io","type":"other","archive_url":"https://web.archive.org/web/20260829075527/https://docs.feg.io/resources/feg-upgrade","credibility":3,"archive_timestamp":"2026-08-29T07:55:27+00:00"},{"url":"https://www.scam-detector.com/validator/fegtoken-com-review/","name":"scam-detector.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.quora.com/Is-the-FEG-crypto-token-a-scam","name":"quora.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://fegrox.com/","name":"fegrox.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260711020137/https://en.wikipedia.org/wiki/ZachXBT","credibility":3,"archive_timestamp":"2026-07-11T02:01:37+00:00"},{"url":"https://twitter.com/zachxbt","name":"twitter.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:26.694347+00:00","updated_at":"2026-08-29T23:26:13.385603+00:00"}}