Incident case file
Sign in to watchBonfireSwap Router Missing Access Control — $50K Loss, 41 Victims
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 16, 2026, an attacker exploited a missing access control check in the BonfireSwap router's transfer function on BNB Chain. The function never verified that msg.sender equaled the from address, nor did it check the caller's actual allowance over the from address's tokens. This let the attacker designate any of the router's previously-approved token holders as the from address and themselves as the recipient, draining tokens using pre-existing victim-to-router allowances and forwarding the proceeds through a same-token pool swap. A total of 41 TOKEN holders who had previously approved the router were affected, for a combined loss of approximately $50,000. The largest single loss was over 5,289 TOKEN from one victim address.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)