BlockSec: DBXen contract遭遇攻击,损失约 150,000美元
According to BlockSec monitoring, the DBXen contract was attacked this morning, with estimated losses of about $150,000. The root cause lies in the inconsistency of the sender's identity under the ERC2771 meta-transaction. In the burnBatch() function, the gasWrapper() modifier uses _msgSender() (the actual user) to update the state, while the callback function onTokenBurned() uses msg.sender (the relayer). This leads to accCycleBatchesBurned being recorded for the user, but lastActiveCycle being incorrectly updated for the relayer.
This inconsistency disrupts the logic of claimFees() and claimRewards(). When updateStats() is run for the user, the contract incorrectly assumes there are unprocessed burned batches because accCycleBatchesBurned has been updated while lastActiveCycle has not, resulting in incorrect calculations of rewards and fees, allowing the attacker to extract excess funds for profit.
You may also like

Will the STRC issuance price discussed with ChatGPT really fall into a death spiral?

TRON revitalizes the image of the bull, creating a more approachable brand character
How to Trade Apple and Nvidia on a Crypto Exchange in 2026 (Without Buying Shares)

Exclusive Interview with Strategy CEO: Putting Aside the Sale of 32 BTC, the 60 Trillion AI Intelligence is the Ultimate Fate of Bitcoin

Morning Report | The South Korean Financial Services Commission plans to expand the regulatory sandbox to include virtual assets; the parent company of the New York Stock Exchange, ICE, has reached a partnership with OKX to jointly establish a cryptocu...

Morning Report | Secret Network loses $4.67 million due to cross-chain vulnerability; Michael Saylor releases Bitcoin Tracker information again, may disclose increased holdings data next week

Kalshi's biggest competitor is not Polymarket

The second half of the computing power battle: Intel CEO Pat Gelsinger reveals how AI is reshaping the global semiconductor supply chain

B.AI partners with MiniMax to launch a limited-time free experience of M3, enabling zero-threshold implementation of Agentic productivity through full-stack infrastructure

A company that was on the verge of bankruptcy has just surpassed Bitcoin in market value

The two giants are racing in "credit": loan balances of 9.9 billion vs 14.6 billion USD, Brazil has become the main battlefield

Rented Belief: How Much of the Bitcoin ETF Fund Flow is Real Money

On-chain finance: On-chain IPOs and on-chain ICOs, a new frontier in the trillion-dollar market

WEEX Live mode: Monitor 20 trading pairs at once and trade like a pro

WEEX Makes Affiliate Access Easier on the Web and in the App

Customize Your Spot Trading Page: Drag Modules and Move the Order Panel Where You Want It

Perp DEX: The Next Generation Exchange "War"

