Magic Eden NFT Exploit Highlights Risks of Outdated Wallet Permissions
A recent Magic Eden NFT exploit has raised concerns about outdated wallet permissions. Thousands of non-fungible tokens (NFTs) moved from multiple wallets on September 25, sparking security worries. The incident involved a wallet that transferred assets to itself for zero ETH, leaving users uncertain about the transactions' authenticity.
NFT trader Cirrus was the first to identify suspicious activity involving Magic Eden contracts. They warned users who had previously interacted with Magic Eden to revoke approvals from their wallets. Cirrus suggested that the activity could be a whitehat operation attempting to secure vulnerable assets.
Magic Eden later confirmed that legacy approvals from its former EVM marketplace exposed NFTs valued above $5.7 million. The company stated that no active listings were affected by the vulnerability, which involved Limit Break's Payment Processor V2. Magic Eden stopped using this processor in 2024.
Yuga Labs executive 0xQuit confirmed that a whitehat operation recovered 23,155 NFTs worth over $5.7 million. However, 660 WETH remained exposed and was not recovered during the operation.