ChainCatcher report: According to the SlowMist Security Team, the BonfireSwap router contract suffered a loss of approximately $50,000 due to a missing access control in the transfer function. The function did not verify whether the caller was the "from" address or whether the caller had been authorized by the "from" address to spend its assets. As a result, attackers could set a user who had previously approved the router as the "from" address and themselves as the "to" address, thereby transferring the victim’s tokens and exchanging them through the same token pool. SlowMist stated that a total of 41 TOKEN holders who had previously approved this router were affected. The vulnerable contract address is 0x17e801e17cefc6334059189c178d4783830e03d3.
BonfireSwap Router Vulnerability Results in $50K Loss, Affecting 41 Users
ChaincatcherShare
A recent exploit in BonfireSwap’s router contract resulted in a $50,000 loss in the crypto market, affecting 41 users. The vulnerability arose from a missing access control in the transfer function, allowing attackers to drain tokens from previously authorized accounts. The affected contract is 0x17e801e17cefc6334059189c178d4783830e03d3. As altcoins to watch gain attention, this incident underscores the ongoing risks in DeFi protocols.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.