Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

DBXen Staking Hack: Attacker Exploits ERC2771 Bug to Drain $150K

Security firm BlockSec Phalcon says DBXen bug lets the system confuse the user and forwarder, letting attackers claim extra rewards from staking contracts.

Written By Kenrodgers Fabian Kenrodgers Fabian
Fact Checked by Dishita Malvania Dishita Malvania
Published March 12, 2026 4:12 PM
Make The Crypto Times preferred on GoogleGoogle
Share
DBXen Staking Hack Attacker Exploits ERC2771 Bug to Drain $150K

Key Highlights

  • DBXen hack exploited ERC2771 mismatch, letting attackers claim years of rewards instantly.
  • Permissionless forwarders still risk miscalculating fees, leaving staking contracts vulnerable.
  • Repeated burn-cycle and sender bugs show smart contracts remain exposed to high-value exploits.

DBXen, a decentralized finance (DeFi) platform, suffered a major contract exploit on Thursday morning, resulting in an estimated $150,000 loss, according to blockchain security monitor BlockSec Phalcon.

The attack exploited flaws in ERC2771 meta-transactions—a system that lets users interact with smart contracts through a “forwarder” address to simplify transaction handling. The bug arose from how DBXen tracked who was performing a transaction. While the burnBatch() function correctly recorded the actual user, the onTokenBurned() callback mistakenly referenced the forwarder’s address.

This mismatch caused the system to treat the forwarder as the active participant, allowing the attacker to manipulate rewards and fees and drain extra tokens from the contract.

BlockSec Phalcon highlighted this as a cautionary tale for DeFi projects relying on meta-transaction frameworks without thorough auditing.

ALERT! Our system detected suspicious transactions targeting @DBXen_crypto's contract hours ago, resulting in an estimated loss of ~$150K. The root cause is an inconsistent sender identity under ERC2771 meta-transactions, which allowed the attacker to manipulate the reward… pic.twitter.com/qVt9JkDSfw

— BlockSec Phalcon (@Phalcon_xyz) March 12, 2026

The exploit targeted DBXen’s staking system, which generates $DXN tokens when users burn $XEN, a process meant to reduce the overall supply of XEN.

According to TreeCityWes.xen on X, the attacker took advantage of two issues: an open (permissionless) transaction forwarder and a bug in the fee system that applies to newly created addresses. By posing as a brand-new user, the attacker tricked the contract into thinking they had been staking for a long time, allowing them to claim a large amount of accumulated rewards.

“The protocol effectively backdated a brand new address to cycle 0 and paid it 3 years of fee income,” the post explained. In total, the attacker drained 65.28 ETH and minted 2,305 DXN, moving funds out via LayerZero within minutes.

HOLY SHIT – DBXEN STAKING HACK.

A Thread 🧵…

DBXEN staking contract was drained for 65.28 ETH in a single exploit. The attacker combined a permissionless trusted forwarder with a fee accounting bug for fresh addresses, spoofed _msgSender(), called burnBatch(5560), and walked… pic.twitter.com/zcM9o2KWJZ

— TreeCityWes.xen (@TreeCityWes) March 12, 2026

ERC2771 bug and fee accounting flaws

The attack happened because DBXen got confused about who was actually sending transactions. The system used two ways to check the sender—_msgSender() and msg.sender—but they didn’t match. This mismatch broke the reward calculations in claimFees() and claimRewards(), letting the attacker claim way more than they should. 

On top of that, brand-new addresses were treated as if they’d been staking for years, receiving all the accumulated fees from 1,085 cycles.

This kind of problem has happened before. In February 2026, hackers hit the BNB Smart Chain, stealing over $438,000 from SOF and LAXO tokens. They exploited glitches in the burn functions, which let them inflate token values and manipulate liquidity pools. Still in February, Ethereum and Base networks saw a $2.26 million FOOMCASH hack caused by misconfigured zkSNARK verification keys, showing that repeated mistakes keep leaving smart contracts vulnerable.

Lessons from recurring exploits

DBXen’s breach isn’t a one-off; it’s a clear example of the recurring ERC2771 sender-inconsistency problem. The permissionless forwarders are still being used without making sure every state update correctly tracks the sender. 

Adding to this, weak business logic around burn cycles makes these systems even more vulnerable. Protocols keep shipping permissionless forwarders without ensuring every single state update uses the same sender resolution

Developers need to carefully audit forwarders and make sure every function consistently references the correct sender. Beyond the financial loss, these exploits show that staking protocols with complicated reward cycles remain exposed. Without immediate fixes, similar attacks could keep happening across new token ecosystems.

Also Read: BONK.fun Hack Exposes Users to Wallet Drainer Threat

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Demo Live
Prediction Market Fight May Reach Supreme Court CFTC Chair Selig
Prediction Market Fight May Reach Supreme Court: CFTC Chair Selig
Anchorage Bets Big on AI Economy With New Banking Model
Anchorage Bets Big on AI Economy With New Banking Model
Tapnob Rolls Out Crypto-to-Naira Payment Platform in Nigeria
Tapnob Rolls Out Crypto-to-Naira Payment Platform in Nigeria
Clarity Act on Fast Track Senator Moreno Sets July 4 Deadline
Clarity Act on Fast Track? Senator Moreno Sets July 4 Deadline

Find Us on Socials

You may also like

$295M Hack Fallout: Drift Protocol Rolls Out User Recovery Plan

$295M Hack Fallout: Drift Protocol Rolls Out User Recovery Plan

Aave vs Gerstein: Harrow Court Clash Over $71M Stolen ETH Linked to Kelp DAO Hack

Aave vs Gerstein Harrow: Court Clash Over $71M Stolen ETH Linked to Kelp DAO Hack

Ripple Teams Up with Crypto ISAC to Stop North Korean Hackers

Ripple Teams Up with Crypto ISAC to Stop North Korean Hackers

Aave Files Motion to Unfreeze $71M ETH Tied to KelpDAO Exploit

Aave Files Motion to Unfreeze $71M ETH Tied to KelpDAO Exploit

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information