金色财经|Sep 16, 2026 07:56
[SlowMist: BonfireSwap Router Contract Attacked, Token Holders Suffer Approximately $50,000 in Losses]
According to a report by Golden Finance on September 16, monitored by SlowMist, BonfireSwap on BSC was attacked, resulting in token holders suffering approximately $50,000 in losses. The cause was the lack of access control in the `transfer` function of its router contract. The function did not check `msg.sender == from` nor verify the caller's authorization limit for `from`, allowing anyone to set the victim as `from` and themselves as `to`. The attacker exploited the pre-authorized limit to deplete the victim's tokens and forwarded funds through token pool exchanges. A total of 41 token holders who authorized the router contract were affected in this incident.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink