Magic Eden Warns of Exploit Affecting Old Ethereum NFT Listings
Users of Magic Eden's old Ethereum marketplace are being warned about an exploit that could leave their NFTs exposed to theft. The issue lies in lingering approvals granted when users list or trade NFTs, which stay active until revoked.
Magic Eden adopted the Payment Processor V2 contract to settle trades on its EVM marketplace between February and October 2024, but stopped using it that October. The company has since shut down its entire EVM marketplace.
The problem was exposed when an attacker used a bug in Payment Processor V2 to steal a significant number of NFTs, including 10 Meebits, 50 Otherdeeds, and 235 Desperate Apewives, as reported by Yuga Labs Vice President of Blockchain 0xQuit.
Limit Break, the company behind Payment Processor V2, was forced to pause its V3 contract due to the same flaw, but the V2 contract couldn't be paused. This led to a whitehat rescue operation where friendly hackers moved vulnerable assets to safety before attackers could.