BonfireSwap Router Vulnerability Leads to $50,000 Theft

A reported vulnerability in BonfireSwap's router resulted in the theft of approximately $50,000 (about 68 million KRW) worth of TOKEN. The victims were identified as 41 users who had previously approved the router. SlowMist security team disclosed on X that the router's transfer function failed to verify if the caller matched the 'from' address or if the caller had been authorized to use the assets from that address. Attackers exploited this by setting victim addresses as 'from' and their own addresses as 'to', transferring pre-approved tokens and swapping them within the same TOKEN pool. The vulnerable router contract address is 0x17e801e17cefc6334059189c178d4783830e03d3.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: BonfireSwap 접근 제어 누락…5만달러 손실