Magic Eden Says Legacy Approvals Exposed $5.7M In NFTs To Exploit

비트코인 양자 저항 거래 성공

TL;DR

An old smart contract can remain dangerous long after the product built around it has disappeared.

Magic Eden is dealing with exactly that problem after legacy approvals from its former EVM marketplace left thousands of NFTs exposed to a vulnerability in Limit Break’s Payment Processor V2.

The marketplace says more than $5.7 million worth of NFTs were at risk.

The Marketplace Was Closed, But The Approvals Were Still Live

Magic Eden stopped using Payment Processor V2 in October 2024 and later shut down its EVM marketplace.

That did not automatically revoke permissions users had previously granted to the contract.

When an attacker exploited the processor this week, those old approvals became relevant again.

The initial theft included assets from collections such as Meebits, Otherdeeds and World of Women.

Security researchers then realized a much larger number of wallets remained exposed.

A whitehat rescue operation ultimately secured 23,155 NFTs worth more than $5.7 million before they could be taken.

Users are expected to reclaim rescued assets after revoking the vulnerable approval.

Magic Eden says no active listings on its current products were affected.

Token Approvals Can Outlive The App That Asked For Them

The incident is a useful reminder of how wallet permissions work.

When a user gives a marketplace or protocol permission to transfer assets, that authorization can remain valid until it is explicitly revoked.

Closing a website does not necessarily remove it.

Changing marketplaces does not necessarily remove it.

Even abandoning a wallet interface does not alter what has already been approved onchain.

Magic Eden says users who interacted with its EVM marketplace during the affected period should revoke Payment Processor V2 permissions on supported networks including Ethereum, Polygon and Base.

Researchers also identified a related route that placed hundreds of WETH at risk, showing that the vulnerability was not limited to NFTs.

The technical exploit sits inside Limit Break’s processor rather than Magic Eden’s live marketplace.

But old Magic Eden approvals dramatically expanded the number of users potentially exposed.

Crypto security often focuses on what somebody is signing today.

This incident shows why the permissions granted years ago can matter just as much.

This article was written by the News Desk and edited by Samuel Rae.

Exit mobile version