๐จSlowMist TI Alert๐จ
๐ธ
@Bonfiretoken Loss: ~ $50k
๐ Root Cause: Access control missing in BonfireSwap router's `transfer`. The function does not check `msg.sender == from` nor verify the caller's allowance on `from`, letting anyone set a victim as `from` and themselves as `to`. The router drains the victim's TOKEN using its pre-approved allowance (victim โ router) and forwards funds via same-token pool swap.
๐ Attacker: 0x2b5bf7d9d9dc1eec68f40c6b7a8f197e65f9731a โ attack contract 0x28E976Ea7b83553d6D1D45CE81334156A2632127
๐ Victim: 41 TOKEN holders who approved the router (largest: 0xefF2FC4E3145f58F534d68A36Bcd3085Be6a4096, โ5289.1 TOKEN)
๐ Vulnerable Contract: 0x17e801e17cefc6334059189c178d4783830e03d3 (BonfireSwap router)
Powered by
Tx: