Magic Eden Users Left Exposed by Lingering Approval Vulnerability
Users who traded on Magic Eden's Ethereum marketplace before it ended support in March may be at risk due to lingering approvals.
A September warning from Revoke.cash, a wallet security service, revealed that old Magic Eden operator approvals remain active even after the company closed its EVM marketplace. This vulnerability in Limit Break's Payment Processor V2 allows anyone with approval to move NFTs, including malicious actors.
Security researcher 0xQuit recently moved 3,832 NFTs using this vulnerability as a 'whitehat rescue,' holding them in a custody wallet until it is safe to return. However, Revoke.cash warns that users should revoke Payment Processor V2 approval on Ethereum and Payment Processor V3 approval on ApeChain.
This means users need to check their old permissions rather than relying on canceling listings or disconnecting wallets, as this will not remove onchain permissions. Revoking access is a preventive measure to reduce future exposure but does not retrieve assets already taken.