← Radar

Incident case file

Sign in to watch

BonfireSwap Router Missing Access Control — $50K Loss, 41 Victims

Incident date Sep 15, 2026Last updated Sep 24, 2026

0 views

ContainedBNB ChainMissing access control on router transferCluster: BONFIRE-BNB-2026-09

Estimated loss

$50K

Affected users

41
Group joining is coming soon.

Investigation

90%

Facts and investigation

Ledger

Attacker

0x2b5bf7d9d9dc1eec68f40c6b7a8f197e65f9731a

Funds moved to

Drained directly from 41 pre-approved token holders via existing router allowances, forwarded through a same-token pool swap.

Linked

Attacker: 0x2b5bf7d9d9dc1eec68f40c6b7a8f197e65f9731a. Attack contract: 0x28E976Ea7b83553d6D1D45CE81334156A2632127. Vulnerable router: 0x17e801e17cefc6334059189c178d4783830e03d3. Largest individual victim: 0xefF2FC4E3145f58F534d68A36Bcd3085Be6a4096 (-5,289.1 TOKEN). Attack transaction: 0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f.

Chronology

1 beat
  1. On September 16, 2026, an attacker exploited a missing access control check in the BonfireSwap router's transfer function on BNB Chain. The function never verified that msg.sender equaled the from address, nor did it check the caller's actual allowance over the from address's tokens. This let the attacker designate any of the router's previously-approved token holders as the from address and themselves as the recipient, draining tokens using pre-existing victim-to-router allowances and forwarding the proceeds through a same-token pool swap. A total of 41 TOKEN holders who had previously approved the router were affected, for a combined loss of approximately $50,000. The largest single loss was over 5,289 TOKEN from one victim address.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)