BomFireSwap Routing Contract Attack Causes $50,000 Loss for 41 Token Holders

Blockchain security company SlowMist reported on X that an attack exploiting a flaw in BomFireSwap's routing contract resulted in 41 token holders losing assets worth approximately $50,000 (68 million KRW). The breach occurred when attackers exploited an access control vulnerability in the transfer function of the routing contract, which failed to properly verify whether the withdrawal address matched the caller and whether the withdrawal address had been approved for use. Attackers were able to designate victim addresses as withdrawal addresses by manipulating this flaw.
SlowMist explained that attackers first moved tokens from wallets with pre-approved usage permissions into the routing contract before exchanging the same tokens in liquidity pools to siphon off assets. The largest single loss was 5,289.1 tokens from one address.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 본파이어스왑 라우팅 계약 공격…토큰 보유자 6800만원 손실