扫码下载
BTC $62,198.90 +2.76%
ETH $1,634.30 +5.14%
BNB $596.14 +3.87%
XRP $1.12 +5.65%
SOL $65.23 +5.76%
TRX $0.3275 +1.72%
DOGE $0.0846 +4.78%
ADA $0.1624 +3.19%
BCH $224.94 +5.06%
LINK $7.73 +5.69%
HYPE $58.92 +3.98%
AAVE $62.63 +3.75%
SUI $0.7475 +5.71%
XLM $0.2064 -0.73%
ZEC $415.63 +16.42%
BTC $62,198.90 +2.76%
ETH $1,634.30 +5.14%
BNB $596.14 +3.87%
XRP $1.12 +5.65%
SOL $65.23 +5.76%
TRX $0.3275 +1.72%
DOGE $0.0846 +4.78%
ADA $0.1624 +3.19%
BCH $224.94 +5.06%
LINK $7.73 +5.69%
HYPE $58.92 +3.98%
AAVE $62.63 +3.75%
SUI $0.7475 +5.71%
XLM $0.2064 -0.73%
ZEC $415.63 +16.42%

BlockSec:DBXen 合约遭遇攻击,损失约 15 万美元

2026-03-12 16:10:07
收藏

ChainCatcher 消息,据 BlockSec 监测,DBXen 合约今日上午遭遇攻击,估计损失约 15 万美元。根本原因在于 ERC2771 元交易下发送者身份不一致。在 burnBatch() 函数中,gasWrapper() 修饰器使用 _msgSender()(实际用户)更新状态,而回调函数 onTokenBurned() 使用 msg.sender(转发器)。这导致 accCycleBatchesBurned 为用户记录,但 lastActiveCycle 错误地为转发器更新。

该不一致性破坏了 claimFees() 和 claimRewards() 的逻辑。当为用户运行 updateStats() 时,合约错误地认为存在未处理的已销毁批次,因为 accCycleBatchesBurned 已更新而 lastActiveCycle 未更新,从而错误计算奖励和费用,使攻击者能够提取超额资金获利。

app_icon
ChainCatcher 与创新者共建Web3世界