Bonfiretoken Incident Involves $50,000 Loss Due to Access Control Flaw
An access control vulnerability in the BonfireSwap router led to a loss of approximately $50,000. The incident affected around 41 approved holders of the token.
The BonfireSwap router experienced a security incident where it lacked proper access control mechanisms. Specifically, it did not enforce that msg.sender was equal to from or check the caller’s allowance on from. This oversight allowed an attacker to exploit the system by setting approved holders as from and themselves as to, which enabled them to drain TOKEN through existing allowances from victims to the router.
The attacker executed the exploit by forwarding the stolen funds through a same-token pool swap. This incident impacted about 41 approved holders, resulting in a total loss estimated at $50,000. The incident occurred on the Ethereum chain, which means that the transactions can be traced on this blockchain, but specific addresses involved in the incident are not provided.
