BonfireSwap Router Vulnerability Causes $50,000 Loss for 41 Users

A reported vulnerability in BonfireSwap's router has caused an estimated $50,000 (approximately 68 million KRW) in damages. Forty-one token holders who had previously approved the router were affected, according to PANews citing SlowMist security team.
SlowMist explained that the router's transfer function failed to verify whether the caller was the 'from' address or if they held permission to use the assets at that address. Attackers exploited this by setting victims as the 'from' address and themselves as the 'to' address, moving tokens from approved pools before swapping them within the same token pool.
The vulnerable router contract address is 0x17e801e17cefc6334059189c178d4783830e03d3.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: BonfireSwap 라우터 취약점…41명에 5만달러 피해