BonfireSwap router access control vulnerability resulted in a loss of approximately $50,000, affecting 41 users
According to the Slow Mist security team, the BonfireSwap router contract suffered a loss of approximately $50,000 due to a lack of access control in the transfer function. This function did not verify whether the caller was the from address, nor did it check the caller's authorization for the assets of the from address. As a result, attackers could set users who had pre-authorized the router as the from address and themselves as the to address, thereby stealing the victim's TOKEN and exchanging it through the same token pool.
Slow Mist stated that a total of 41 TOKEN holders who had authorized the router were affected; the vulnerable contract address is 0x17e801e17cefc6334059189c178d4783830e03d3.
Related tags






