Magic Eden Exploit: Stale Approvals Drain Millions from Wallets
A recent exploit on the Magic Eden marketplace has resulted in the theft of $2.8 million worth of NFTs and tokens, according to tracking services.
The attack targeted wallets that had approved Limit Break's Payment Processor V2 contract years earlier, despite Magic Eden having stopped using it in October 2024.
The vulnerability, known as forwarder spoofing, allowed attackers to forge the sender identity behind a forwarded transaction, enabling them to move NFTs and tokens without a fresh signature.
A white-hat team led by Yuga Labs' 0xQuit successfully rescued 23,155 NFTs worth over $5.7 million into a protective custody wallet, preventing further losses.