Paidun said that it analyzed the latest FEG hacking incident, and the root cause seems to be a composability problem when integrating with the underlying Wormhole bridge used for cross-chain message/token transfers.
Specifically, the hacker created a fake deposit message (through an unexpected Wormhole relay interface, which is not supported by the audited FEG SmartBridge), which was then transmitted to another chain and received by the FEG SmartBridge (now disabled) to withdraw FEG tokens. Note that the SmartDeFi code was not affected in any way.
Meanwhile, the Wormhole Foundation said: "The FEG security incident has nothing to do with Wormhole. All Wormhole contracts are completely unaffected and have nothing to do with this issue."
Previously, FEG was suspected of losing about $1 million in an attack.