BlockSec: DBXen contract遭遇攻击,损失约 150,000美元

By: rootdata|2026/03/12 16:48:00
0
Share
copy

According to BlockSec monitoring, the DBXen contract was attacked this morning, with estimated losses of about $150,000. The root cause lies in the inconsistency of the sender's identity under the ERC2771 meta-transaction. In the burnBatch() function, the gasWrapper() modifier uses _msgSender() (the actual user) to update the state, while the callback function onTokenBurned() uses msg.sender (the relayer). This leads to accCycleBatchesBurned being recorded for the user, but lastActiveCycle being incorrectly updated for the relayer.

This inconsistency disrupts the logic of claimFees() and claimRewards(). When updateStats() is run for the user, the contract incorrectly assumes there are unprocessed burned batches because accCycleBatchesBurned has been updated while lastActiveCycle has not, resulting in incorrect calculations of rewards and fees, allowing the attacker to extract excess funds for profit.

You may also like

Will the STRC issuance price discussed with ChatGPT really fall into a death spiral?

Whether this mechanism is a "stabilizer" or an "accelerator" lies in the upcoming prices and interest rates.

TRON revitalizes the image of the bull, creating a more approachable brand character

From Logo to BoNiu, TRON further enhances its brand visual assets.

How to Trade Apple and Nvidia on a Crypto Exchange in 2026 (Without Buying Shares)

What are Apple and Nvidia stock futures, and why are crypto traders paying attention? Learn how to trade stock futures with USDT, how they differ from buying stocks, and why platforms like WEEX are expanding beyond Bitcoin in 2026.

Exclusive Interview with Strategy CEO: Putting Aside the Sale of 32 BTC, the 60 Trillion AI Intelligence is the Ultimate Fate of Bitcoin

Strategy CEO responds for the first time to the controversy over the sale of 32 bitcoins: testing internal processes and breaking the "death spiral" rhetoric, maintaining long-term holding faith, and revealing how the 60 trillion AI intelligence will reshape the bitcoin trading landscape.

Morning Report | The South Korean Financial Services Commission plans to expand the regulatory sandbox to include virtual assets; the parent company of the New York Stock Exchange, ICE, has reached a partnership with OKX to jointly establish a cryptocu...

Overview of Important Market Events on June 22

Morning Report | Secret Network loses $4.67 million due to cross-chain vulnerability; Michael Saylor releases Bitcoin Tracker information again, may disclose increased holdings data next week

Overview of Important Market Events on June 21

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com