DBXen Hack
What happened
On March 11, 2026, DBXen reward-distribution contracts on Ethereum and BNB Smart Chain were drained for roughly $149,000 through an ERC-2771 sender-identity mismatch.
DBXen inconsistently used msg.sender and ERC-2771 _msgSender() across burn and active-cycle accounting, separating the address charged for burns from the address credited for rewards.
How it happened
Forwarded burn calls credited the real signer in one part of DBXen's accounting while another part treated the trusted forwarder as the sender. The resulting state mismatch allowed repeated reward claims until the pool was depleted.
Protocol details
Market Context at Time of Hack
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.