BlockSec: DBXen contract遭遇攻击,损失约 150,000美元
According to BlockSec monitoring, the DBXen contract was attacked this morning, with estimated losses of about $150,000. The root cause lies in the inconsistency of the sender's identity under the ERC2771 meta-transaction. In the burnBatch() function, the gasWrapper() modifier uses _msgSender() (the actual user) to update the state, while the callback function onTokenBurned() uses msg.sender (the relayer). This leads to accCycleBatchesBurned being recorded for the user, but lastActiveCycle being incorrectly updated for the relayer.
This inconsistency disrupts the logic of claimFees() and claimRewards(). When updateStats() is run for the user, the contract incorrectly assumes there are unprocessed burned batches because accCycleBatchesBurned has been updated while lastActiveCycle has not, resulting in incorrect calculations of rewards and fees, allowing the attacker to extract excess funds for profit.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

IonQ Superion 256 Becomes the First System Deployed at NVIDIA Quantum Research Center

Administrators of Coinhouse.eu embezzled €125,492 in customer crypto

Coinbase files for perpetual futures on US stocks, CFTC approval pending

Nimiq Attacked on Polygon, Losses Approximately $504,000

U.S. Federal Register Website Launches AI Search Function for China's Qwen Model

Aqua Resumes Lightning and Liquid Exchange Functionality Through Indra

AWS Reveals AI Agent's Automatic Payment Case with USDC

ether.fi Loses Approximately 15.45 ETH Due to AtomicQueue Contract Vulnerability

China Establishes International Alliance Against Telecom Network Fraud

Metro-Timer App Launched for Kyiv Metro

London Stock Exchange Partners with Payward to Tokenize 100 UK Stocks

The Government Officialized New Salary Supplements for Security Forces: Who Receives Them and How Much

Fed's Kashkari Emphasizes the Importance of Policy Reaction Mechanism

METRO Suspends Operations in Zaporizhzhia from August 1

ENS DAO Proposal Establishes New Security Council with Term Until July 2028

Slow Mist: EIP-7702 account vulnerability exploited, 1,988.5 QNT stolen

Qwen 35B cracks complex mathematical techniques, and Vitalik praises its reasoning ability as impressive

Shielded Bitcoin: the proposal that aims to bring privacy without changing BTC's code

End of Bets in Brazil: What Changes and What Are the Next Steps

Galaxy Research: CFTC's 'Mention Markets' Guidance Highlights Structural Manipulation Risks in Individual Speech Predictions

What is CBDC? Governments Push for Development of Central Bank Digital Currencies

Why cash hoarding in the UK proves the world still craves permissionless money

OG.com Submits Application for US Stock Perpetual Contracts to CFTC Following Coinbase, Kalshi, and Kraken's Parent Company Payward

Crypto: $2.1 trillion evaporated, on-chain economy only loses 1.6%

Trump Rejects Iran Ceasefire, Expects Bombing After Midterms: Will Oil and Bitcoin Hold?

Solana’s Alpenglow upgrade reaches devnet with 150ms finality target

Bull Signal for Bitcoin: In 4 out of 5 Past Instances, Prices Increased

Statement on the Misreporting of the Fomo App by BlockBeats

Ripple’s RLUSD supply nears $2.5B as XRPL stablecoins climb 6%

