Data: Approximately 62.28 BNB lost, a certain Router on BNB Chain was attacked
According to Slow Fog monitoring, a certain Router contract was attacked due to security flaws in the Swap entry and uniswapV3SwapCallback, resulting in a loss of approximately 62.28 BNB.
The Router did not verify whether the caller was a legitimate V3 Pool, and it also failed to bind the payer in the callback to the original transaction context. The attacker forged a V3 Pool/adapter and injected the victim's address as the payer, utilizing the ERC-20 authorization previously granted to the Router by the user to execute transferFrom() and transfer assets. Users who had previously granted sufficient token authorization to the Router may have their authorized assets transferred away even without further interaction.






