Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

DBXen Staking Hack: Attacker Exploits ERC2771 Bug to Drain $150K

Security firm BlockSec Phalcon says DBXen bug lets the system confuse the user and forwarder, letting attackers claim extra rewards from staking contracts.

Written By:
Kenrodgers Fabian

Reviewed By:
Dishita Malvania

Last updated: March 12, 2026 4:12 PM
Published March 12, 2026 4:12 PM
Share
Last updated: March 12, 2026 4:12 PM
Published March 12, 2026 4:12 PM
DBXen Staking Hack Attacker Exploits ERC2771 Bug to Drain $150K

Key Highlights

  • DBXen hack exploited ERC2771 mismatch, letting attackers claim years of rewards instantly.
  • Permissionless forwarders still risk miscalculating fees, leaving staking contracts vulnerable.
  • Repeated burn-cycle and sender bugs show smart contracts remain exposed to high-value exploits.

DBXen, a decentralized finance (DeFi) platform, suffered a major contract exploit on Thursday morning, resulting in an estimated $150,000 loss, according to blockchain security monitor BlockSec Phalcon.

The attack exploited flaws in ERC2771 meta-transactions—a system that lets users interact with smart contracts through a “forwarder” address to simplify transaction handling. The bug arose from how DBXen tracked who was performing a transaction. While the burnBatch() function correctly recorded the actual user, the onTokenBurned() callback mistakenly referenced the forwarder’s address.

This mismatch caused the system to treat the forwarder as the active participant, allowing the attacker to manipulate rewards and fees and drain extra tokens from the contract.

BlockSec Phalcon highlighted this as a cautionary tale for DeFi projects relying on meta-transaction frameworks without thorough auditing.

ALERT! Our system detected suspicious transactions targeting @DBXen_crypto's contract hours ago, resulting in an estimated loss of ~$150K. The root cause is an inconsistent sender identity under ERC2771 meta-transactions, which allowed the attacker to manipulate the reward… pic.twitter.com/qVt9JkDSfw

— BlockSec Phalcon (@Phalcon_xyz) March 12, 2026

The exploit targeted DBXen’s staking system, which generates $DXN tokens when users burn $XEN, a process meant to reduce the overall supply of XEN.

According to TreeCityWes.xen on X, the attacker took advantage of two issues: an open (permissionless) transaction forwarder and a bug in the fee system that applies to newly created addresses. By posing as a brand-new user, the attacker tricked the contract into thinking they had been staking for a long time, allowing them to claim a large amount of accumulated rewards.

“The protocol effectively backdated a brand new address to cycle 0 and paid it 3 years of fee income,” the post explained. In total, the attacker drained 65.28 ETH and minted 2,305 DXN, moving funds out via LayerZero within minutes.

HOLY SHIT – DBXEN STAKING HACK.

A Thread 🧵…

DBXEN staking contract was drained for 65.28 ETH in a single exploit. The attacker combined a permissionless trusted forwarder with a fee accounting bug for fresh addresses, spoofed _msgSender(), called burnBatch(5560), and walked… pic.twitter.com/zcM9o2KWJZ

— TreeCityWes.xen (@TreeCityWes) March 12, 2026

ERC2771 bug and fee accounting flaws

The attack happened because DBXen got confused about who was actually sending transactions. The system used two ways to check the sender—_msgSender() and msg.sender—but they didn’t match. This mismatch broke the reward calculations in claimFees() and claimRewards(), letting the attacker claim way more than they should. 

On top of that, brand-new addresses were treated as if they’d been staking for years, receiving all the accumulated fees from 1,085 cycles.

This kind of problem has happened before. In February 2026, hackers hit the BNB Smart Chain, stealing over $438,000 from SOF and LAXO tokens. They exploited glitches in the burn functions, which let them inflate token values and manipulate liquidity pools. Still in February, Ethereum and Base networks saw a $2.26 million FOOMCASH hack caused by misconfigured zkSNARK verification keys, showing that repeated mistakes keep leaving smart contracts vulnerable.

Lessons from recurring exploits

DBXen’s breach isn’t a one-off; it’s a clear example of the recurring ERC2771 sender-inconsistency problem. The permissionless forwarders are still being used without making sure every state update correctly tracks the sender. 

Adding to this, weak business logic around burn cycles makes these systems even more vulnerable. Protocols keep shipping permissionless forwarders without ensuring every single state update uses the same sender resolution

Developers need to carefully audit forwarders and make sure every function consistently references the correct sender. Beyond the financial loss, these exploits show that staking protocols with complicated reward cycles remain exposed. Without immediate fixes, similar attacks could keep happening across new token ecosystems.

Also Read: BONK.fun Hack Exposes Users to Wallet Drainer Threat

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Dishita Malvania - Senior crypto journalist at The Crypto Times
By Dishita Malvania
Follow:
Dishita Malvania is a Crypto Journalist with 3 years of experience covering the evolving landscape of blockchain, Web3, AI, finance, and B2B tech. With a background in Computer Science and Digital Media, she blends technical knowledge with sharp editorial insight. Dishita reports on key developments in the crypto world—including Litecoin, WazirX, Solana, Cardano, and broader blockchain trends—alongside interviews with notable figures in the space. Her work has been referenced by top digital media outlets like Entrepreneur.com, The Independent, The Verge, and Metro.co, especially on trending topics like Elon Musk, memecoins, Trump, and notable rug pulls.

Latest News

Coinbase CLO Backs Stablecoin Compromise Despite Industry Pushback
Coinbase CLO Backs Stablecoin Compromise Despite Industry Pushback
U.S. Traders Get Margin Access as Kraken Goes Regulated
U.S. Traders Get Margin Access as Kraken Goes Regulated
CFTC Targets Minnesota as Prediction Market Battle Expands
CFTC Targets Minnesota as Prediction Market Battle Expands
Ondo, JPMorgan, Ripple Complete First Cross-Border Treasury Redemption
Ondo, JPMorgan, Ripple Complete First Cross-Border Treasury Redemption
From ETFs to AI: Eric Trump Explains Why U.S. Will Win Crypto
From ETFs to AI: Eric Trump Explains Why U.S. Will Win Crypto

Find Us on Socials

You may also like

Ekubo Protocol Exploit Sees $1.4M Drained in 85 Transactions

Ekubo Protocol Exploit Sees $1.4M Drained in 85 Transactions

KelpDAO Blames LayerZero, Shifts to Chainlink’s CCIP After $292M Hack

KelpDAO Blames LayerZero, Shifts to Chainlink’s CCIP After $292M Hack

$295M Hack Fallout: Drift Protocol Rolls Out User Recovery Plan

$295M Hack Fallout: Drift Protocol Rolls Out User Recovery Plan

Aave vs Gerstein: Harrow Court Clash Over $71M Stolen ETH Linked to Kelp DAO Hack

Aave vs Gerstein Harrow: Court Clash Over $71M Stolen ETH Linked to Kelp DAO Hack

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information