BlockSec: DBXen contract遭遇攻击,损失约 150,000美元
According to BlockSec monitoring, the DBXen contract was attacked this morning, with estimated losses of about $150,000. The root cause lies in the inconsistency of the sender's identity under the ERC2771 meta-transaction. In the burnBatch() function, the gasWrapper() modifier uses _msgSender() (the actual user) to update the state, while the callback function onTokenBurned() uses msg.sender (the relayer). This leads to accCycleBatchesBurned being recorded for the user, but lastActiveCycle being incorrectly updated for the relayer.
This inconsistency disrupts the logic of claimFees() and claimRewards(). When updateStats() is run for the user, the contract incorrectly assumes there are unprocessed burned batches because accCycleBatchesBurned has been updated while lastActiveCycle has not, resulting in incorrect calculations of rewards and fees, allowing the attacker to extract excess funds for profit.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Nimiq Attacked on Polygon, Losses Approximately $504,000

U.S. Federal Register Website Launches AI Search Function for China's Qwen Model

Aqua Resumes Lightning and Liquid Exchange Functionality Through Indra

AWS Reveals AI Agent's Automatic Payment Case with USDC

ether.fi Loses Approximately 15.45 ETH Due to AtomicQueue Contract Vulnerability

Fed's Kashkari Emphasizes the Importance of Policy Reaction Mechanism

METRO Suspends Operations in Zaporizhzhia from August 1

ENS DAO Proposal Establishes New Security Council with Term Until July 2028

Slow Mist: EIP-7702 account vulnerability exploited, 1,988.5 QNT stolen

Qwen 35B cracks complex mathematical techniques, and Vitalik praises its reasoning ability as impressive

Open-source Memecoin launchpad adds 1,373 lines of solidity in latest development release

BlackRock says Bitcoin volatility fell to 35–40

Gemini Hacks Three Companies Autonomously: What It Means

France crypto home attack steals €40,000: Report

EU staking review threatens crypto yields and network security could pay the price

DCENT Issues Urgent Security Warning for XRP Users

Cybercriminals Create Fake AI Agents to Install Malware and Steal Cryptocurrencies

Toyosa adds BTC alongside USDT for Toyota purchases

Bitcoin: VanEck Criticizes Metaplanet's Compensation Model

Ethereum sets 2029 quantum target as Hegotá takes shape

Stablecoin salaries can leave workers paying to access their wages

After FomoPeek Theft: You Need This New Private Key Security Guide!

Hong Kong jails ex-banker over $470K USDT bribes

Hut8 Bitcoin Mining Founder Marc van der Chijs: AI May Cause Systemic Shock, Reconfigure Back to BTC

Why is Cryptocurrency Still Rising? A Conversation on Bull Markets, Regulation, Interest Rates, and Stock Tokenization
![[Coin Crime] "If you give us Tether, we will give you oil" - Polish state-owned company falls victim to international fraudsters](/public-static/18_26310349ce.png?format=avif)
[Coin Crime] "If you give us Tether, we will give you oil" - Polish state-owned company falls victim to international fraudsters

Why real-time election odds are misleading prediction market crypto traders

Ripple says asset managers prepare for XRPL Batch

500 agents and £500 million: London aims to track dirty money everywhere










