Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

DBXen Staking Hack: Attacker Exploits ERC2771 Bug to Drain $150K

Security firm BlockSec Phalcon says DBXen bug lets the system confuse the user and forwarder, letting attackers claim extra rewards from staking contracts.

Written By Kenrodgers Fabian
Fact Checked by Dishita Malvania
Published 2026-03-12
Make The Crypto Times preferred on GoogleGoogle
DBXen Staking Hack Attacker Exploits ERC2771 Bug to Drain $150K

Key Highlights

  • DBXen hack exploited ERC2771 mismatch, letting attackers claim years of rewards instantly.
  • Permissionless forwarders still risk miscalculating fees, leaving staking contracts vulnerable.
  • Repeated burn-cycle and sender bugs show smart contracts remain exposed to high-value exploits.

DBXen, a decentralized finance (DeFi) platform, suffered a major contract exploit on Thursday morning, resulting in an estimated $150,000 loss, according to blockchain security monitor BlockSec Phalcon.

The attack exploited flaws in ERC2771 meta-transactions—a system that lets users interact with smart contracts through a “forwarder” address to simplify transaction handling. The bug arose from how DBXen tracked who was performing a transaction. While the burnBatch() function correctly recorded the actual user, the onTokenBurned() callback mistakenly referenced the forwarder’s address.

This mismatch caused the system to treat the forwarder as the active participant, allowing the attacker to manipulate rewards and fees and drain extra tokens from the contract.

BlockSec Phalcon highlighted this as a cautionary tale for DeFi projects relying on meta-transaction frameworks without thorough auditing.

ALERT! Our system detected suspicious transactions targeting @DBXen_crypto's contract hours ago, resulting in an estimated loss of ~$150K. The root cause is an inconsistent sender identity under ERC2771 meta-transactions, which allowed the attacker to manipulate the reward… pic.twitter.com/qVt9JkDSfw

— BlockSec Phalcon (@Phalcon_xyz) March 12, 2026

The exploit targeted DBXen’s staking system, which generates $DXN tokens when users burn $XEN, a process meant to reduce the overall supply of XEN.

According to TreeCityWes.xen on X, the attacker took advantage of two issues: an open (permissionless) transaction forwarder and a bug in the fee system that applies to newly created addresses. By posing as a brand-new user, the attacker tricked the contract into thinking they had been staking for a long time, allowing them to claim a large amount of accumulated rewards.

“The protocol effectively backdated a brand new address to cycle 0 and paid it 3 years of fee income,” the post explained. In total, the attacker drained 65.28 ETH and minted 2,305 DXN, moving funds out via LayerZero within minutes.

HOLY SHIT – DBXEN STAKING HACK.

A Thread 🧵…

DBXEN staking contract was drained for 65.28 ETH in a single exploit. The attacker combined a permissionless trusted forwarder with a fee accounting bug for fresh addresses, spoofed _msgSender(), called burnBatch(5560), and walked… pic.twitter.com/zcM9o2KWJZ

— TreeCityWes.xen (@TreeCityWes) March 12, 2026

ERC2771 bug and fee accounting flaws

The attack happened because DBXen got confused about who was actually sending transactions. The system used two ways to check the sender—_msgSender() and msg.sender—but they didn’t match. This mismatch broke the reward calculations in claimFees() and claimRewards(), letting the attacker claim way more than they should. 

On top of that, brand-new addresses were treated as if they’d been staking for years, receiving all the accumulated fees from 1,085 cycles.

This kind of problem has happened before. In February 2026, hackers hit the BNB Smart Chain, stealing over $438,000 from SOF and LAXO tokens. They exploited glitches in the burn functions, which let them inflate token values and manipulate liquidity pools. Still in February, Ethereum and Base networks saw a $2.26 million FOOMCASH hack caused by misconfigured zkSNARK verification keys, showing that repeated mistakes keep leaving smart contracts vulnerable.

Lessons from recurring exploits

DBXen’s breach isn’t a one-off; it’s a clear example of the recurring ERC2771 sender-inconsistency problem. The permissionless forwarders are still being used without making sure every state update correctly tracks the sender. 

Adding to this, weak business logic around burn cycles makes these systems even more vulnerable. Protocols keep shipping permissionless forwarders without ensuring every single state update uses the same sender resolution

Developers need to carefully audit forwarders and make sure every function consistently references the correct sender. Beyond the financial loss, these exploits show that staking protocols with complicated reward cycles remain exposed. Without immediate fixes, similar attacks could keep happening across new token ecosystems.

Also Read: BONK.fun Hack Exposes Users to Wallet Drainer Threat

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Bitcoin Falls 47% in a Year, Saylor Reveals STRC Up 9% and STRK Down 27%
Bitcoin Falls 47% in a Year, Saylor Reveals STRC Up 9% and STRK Down 27%
Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M
Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M
Tether CEO Denies Blockchain Plans as Stablecoin Operations Grow
Tether CEO Denies Blockchain Plans as Stablecoin Operations Grow
Bitget Restricts HTX, EXMO and 14 Crypto Platforms in Compliance Push
Bitget Restricts HTX, EXMO, and 14 Crypto Platforms in Compliance Push

Find Us on Socials

You may also like

BitGo Takes Lead in $26.6B Real-World Asset Market With 27.5% Share

BitGo Takes Lead in $26.6B Real-World Asset Market With 27.5% Share

Coldcard Attackers Likely Used Unrestricted AI Models, Galaxy Says

Coldcard Attackers Likely Used Unrestricted AI Models, Galaxy Says

Walix Wallet Hack Over $1M in Stolen Crypto Traced to Xhash

Walix Wallet Hack: Over $1M in Stolen Crypto Traced to Xhash

Galaxy Claims Coldcard Attacks Halt After Aug 6

Galaxy Claims Coldcard Attacks Halt After Aug 6

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information