Bonfire Hack
What happened
On September 16, 2026, an attacker executed a batched approval-drain sweep targeting holders of the Bonfire (BONFIRE) token on BNB Chain, resulting in a loss of approximately 66.08 WBNB (~$47.4K USD). T
The attack was executed across two distinct phases within transaction 0xb4c00e8f…92193f. In the harvesting phase, the attacking contract iterated through a pre-compiled list of 65 addresses that had standing approvals to 0x17e801.... Using transferFrom(), the contract pulled each victim's BONFIRE balance directly into the BONFIRE/WBNB liquidity pair. The contract then called swap() to route tokens out to a collector wallet (0x28E976Ea...), netting the inbound deposits against the outbound legs and steadily increasing the pair's token reserves without swapping for WBNB on each individual transfer. The decaying size of the pulled balances across the iterations indicates a script executing against victims ordered by remaining balance size.
In the cash-out phase, the collector address approved the attacking contract and passed its accumulated ~4,576 BONFIRE back into the liquidity pool across two major sell swaps. These swaps extracted 33.223 WBNB and 32.857 WBNB respectively, totaling 66.08 WBNB, which was subsequently unwrapped to native BNB. Standard events such as SwapAndLiquify observed during the execution were simply Bonfire's automated liquidity tax mechanism firing as intended through its legacy PancakeSwap V1 router. The root vulnerability remains off-chain, stemming either from historical phishing campaigns or compromised keys associated with a legacy custom router contract.
Attack Transaction Hash: 0xb4c00e8f…92193f
Harvesting Contract: 0x17e801E1…0E03D3
Collector Address: 0x28E976Ea…632127
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.