logo

BlockSec: DBXen contract遭遇攻击,损失约 150,000美元

By: rootdata|2026/03/12 16:42:00
0
Share
copy

According to BlockSec monitoring, the DBXen contract was attacked this morning, with estimated losses of about $150,000. The root cause lies in the inconsistency of the sender's identity under the ERC2771 meta-transaction. In the burnBatch() function, the gasWrapper() modifier uses _msgSender() (the actual user) to update the state, while the callback function onTokenBurned() uses msg.sender (the relayer). This leads to accCycleBatchesBurned being recorded for the user, but lastActiveCycle being incorrectly updated for the relayer.

This inconsistency disrupts the logic of claimFees() and claimRewards(). When updateStats() is run for the user, the contract incorrectly assumes there are unprocessed burned batches because accCycleBatchesBurned has been updated while lastActiveCycle has not, resulting in incorrect calculations of rewards and fees, allowing the attacker to extract excess funds for profit.

-- Price

--

You may also like

Tom Lee's Ethereum Thesis: Why the Man Who Called the Last Cycle Is Doubling Down on Bitmine

Tom Lee is emerging as one of Ethereum’s most influential supporters. From Fundstrat to Bitmine, his Ethereum thesis combines staking yield, treasury accumulation, and long-term network value. Here is why “Tom Lee Ethereum” has become one of crypto’s most watched narratives.

Naval personally takes the stage: The historic collision between ordinary people and venture capital

Naval personally stepped in as the chairman of the USVC Investment Committee. This SEC-registered fund launched by AngelList attempts to bring top private tech assets like OpenAI, Anthropic, and xAI to the general public with a $500 entry threshold. It is not just a new fund, but a structural experi...

a16z Crypto: 9 Charts to Understand the Evolution Trends of Stablecoins

Stablecoins are evolving from trading tools into universal payment infrastructure, and this process is quieter and more thorough than most people expected.

Refutation of Yang Haipo's "The End of Cryptocurrency"

This may be the true test of cryptocurrency. It's not about whether the price has reached a new high, nor about who will achieve financial freedom in the next bull market, but rather whether, after all the grand narratives have been washed away by cycles, it can still leave behind some simpler, more...

Can a hairdryer earn $34,000? Interpreting the reflexivity paradox of prediction markets

Prediction markets are essentially betting on reality, and when participants can access or even influence this path earlier, the market no longer just reflects reality but begins to shape it in return.

6MV Founder: In 2026, the "landmark turning point" for crypto investment has arrived

"I will deploy funds in 2026, so I will tell you this is the best year in history."

Contents

Popular coins

Latest Crypto News

Read more