Magic Eden Says Legacy Approvals Exposed 5 7M In Nfts To Exploit

BTCC
Paxful


Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

TL;DR

  • Magic Eden says old EVM marketplace approvals left more than $5.7 million worth of NFTs exposed to an exploit in Limit Break’s Payment Processor V2.
  • A whitehat rescue operation moved 23,155 vulnerable NFTs before they could be stolen.
  • Magic Eden says no live listings were affected, but users who interacted with the old marketplace should revoke lingering approvals.

An old smart contract can remain dangerous long after the product built around it has disappeared.

Magic Eden is dealing with exactly that problem after legacy approvals from its former EVM marketplace left thousands of NFTs exposed to a vulnerability in Limit Break’s Payment Processor V2.

Betfury

The marketplace says more than $5.7 million worth of NFTs were at risk.

The Marketplace Was Closed, But The Approvals Were Still Live

Magic Eden stopped using Payment Processor V2 in October 2024 and later shut down its EVM marketplace.

That did not automatically revoke permissions users had previously granted to the contract.

When an attacker exploited the processor this week, those old approvals became relevant again.

The initial theft included assets from collections such as Meebits, Otherdeeds and World of Women.

Security researchers then realized a much larger number of wallets remained exposed.

A whitehat rescue operation ultimately secured 23,155 NFTs worth more than $5.7 million before they could be taken.

Users are expected to reclaim rescued assets after revoking the vulnerable approval.

Magic Eden says no active listings on its current products were affected.

Token Approvals Can Outlive The App That Asked For Them

The incident is a useful reminder of how wallet permissions work.

When a user gives a marketplace or protocol permission to transfer assets, that authorization can remain valid until it is explicitly revoked.

Closing a website does not necessarily remove it.

Changing marketplaces does not necessarily remove it.

Even abandoning a wallet interface does not alter what has already been approved onchain.

Magic Eden says users who interacted with its EVM marketplace during the affected period should revoke Payment Processor V2 permissions on supported networks including Ethereum, Polygon and Base.

Researchers also identified a related route that placed hundreds of WETH at risk, showing that the vulnerability was not limited to NFTs.

The technical exploit sits inside Limit Break’s processor rather than Magic Eden’s live marketplace.

But old Magic Eden approvals dramatically expanded the number of users potentially exposed.

Crypto security often focuses on what somebody is signing today.

This incident shows why the permissions granted years ago can matter just as much.

This article was written by the News Desk and edited by Samuel Rae.

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.



Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*