Magic Eden Users Left Exposed by NFT Payment Processor Vulnerability
A vulnerability in an NFT payment processor has left former Magic Eden users at risk of having their assets transferred without consent. The issue affects users who still have active approvals for the Payment Processor V2 on Ethereum and those who approved Payment Processor V3 on ApeChain. According to Revoke.cash, a security researcher used the vulnerability to move 3,832 NFTs as zero ETH sales, describing the transfers as a 'whitehat rescue.'
The incident highlights that simply canceling a listing or disconnecting a wallet from a website does not protect against onchain approvals. Users who have not traded on Magic Eden since March 9, 2026, are still exposed to this risk.
Revoke.cash advises users to revoke the relevant permissions to prevent further exposure. The service has provided an exploit checker for users to inspect their addresses and take necessary action.