QR 코드를 스캔하여 다운로드하세요.
BTC $61,189.58 -2.23%
ETH $1,578.27 -5.47%
BNB $580.02 -1.17%
XRP $1.09 -3.18%
SOL $63.11 -4.17%
TRX $0.3197 -1.41%
DOGE $0.0820 -2.47%
ADA $0.1589 -1.49%
BCH $223.51 +0.09%
LINK $7.42 -2.07%
HYPE $59.97 -3.30%
AAVE $61.89 -9.34%
SUI $0.7104 +1.02%
XLM $0.2016 +5.20%
ZEC $368.89 +18.85%
BTC $61,189.58 -2.23%
ETH $1,578.27 -5.47%
BNB $580.02 -1.17%
XRP $1.09 -3.18%
SOL $63.11 -4.17%
TRX $0.3197 -1.41%
DOGE $0.0820 -2.47%
ADA $0.1589 -1.49%
BCH $223.51 +0.09%
LINK $7.42 -2.07%
HYPE $59.97 -3.30%
AAVE $61.89 -9.34%
SUI $0.7104 +1.02%
XLM $0.2016 +5.20%
ZEC $368.89 +18.85%

BlockSec: DBXen 계약이 공격을 받아 약 15만 달러의 손실이 발생했습니다

2026-03-12 16:10:07
수집

据 BlockSec 监测,DBXen 合约今日上午遭遇攻击,估计损失约 15 万美元。根本原因在于 ERC2771 元交易下发送者身份不一致。在 burnBatch() 函数中,gasWrapper() 修饰器使用 _msgSender()(实际用户)更新状态,而回调函数 onTokenBurned() 使用 msg.sender(转发器)。这导致 accCycleBatchesBurned 为用户记录,但 lastActiveCycle 错误地为转发器更新。

该不一致性破坏了 claimFees() 和 claimRewards() 的逻辑。当为用户运行 updateStats() 时,合约错误地认为存在未处理的已销毁批次,因为 accCycleBatchesBurned 已更新而 lastActiveCycle 未更新,从而错误计算奖励和费用,使攻击者能够提取超额资金获利。

app_icon
ChainCatcher Building the Web3 world with innovations.