Magic Eden Warns Old Ethereum Listings Exposed to Payment Processor Exploit
Magic Eden is warning users that some of their old NFT listings on Ethereum may be exposed to a payment processor exploit. The marketplace adopted the contract, known as Payment Processor V2, in February 2024 and stopped using it in October of that year.
The issue lies in lingering approvals granted by users when they listed or traded NFTs on Magic Eden's EVM marketplace. These permissions stay active until revoked, allowing an attacker to move the assets. In this case, the attacker used the bug to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives.
A whitehat rescue operation was conducted by friendly hackers, which recovered 23,155 NFTs worth over $5.7 million USD. However, the owners will only be able to reclaim their assets after revoking the approvals on Ethereum, Polygon, and Base using Revoke.cash.