PANews|Sep 16, 2026 07:50
[SlowMist: BonfireSwap Router Access Control Vulnerability Causes $50,000 Loss, 41 Users Affected]
According to the SlowMist security team, the BonfireSwap router contract suffered a loss of approximately $50,000 due to a lack of access control in the transfer function. The function failed to verify whether the caller was the 'from' address and did not check the caller's authorization for the assets of the 'from' address. As a result, attackers were able to set users who had pre-authorized the router as the 'from' address and themselves as the 'to' address, thereby transferring the victim's TOKEN and exchanging it through the same token pool. SlowMist stated that a total of 41 TOKEN holders who had authorized the router were affected. The vulnerable contract address is 0x17e801e17cefc6334059189c178d4783830e03d3.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink