BonfireSwap suffered approximately $50,000 in losses after an access-control flaw in its router contract’s transfer function allowed attackers to move tokens from users who had previously authorized the router. The function did not verify that the caller was the from address or had authorization to use the address’s assets, enabling attackers to designate victims as the source and themselves as the recipient before exchanging the stolen tokens through the same-token pool. A total of 41 token holders who had authorized the router were affected. The vulnerable contract address is 0x17e801e17cefc6334059189c178d4783830e03d3.