Approvals granted by users of Magic Eden to a contract used by the platform in 2024 remained active even after the marketplace abandoned the system. The flaw allowed attacks against old wallets and led researchers to preemptively withdraw more than 23,000 NFTs valued at US$ 5.7 million before they were stolen. Revoke.cash

The problem lies in Payment Processor V2, an NFT trading protocol maintained by Limit Break and adopted by Magic Eden to settle transactions on its old EVM marketplace. The company stopped using the contract in October 2024 and shut down that marketplace in the first quarter of this year, but permissions granted by wallets remained valid. The Block

These authorizations allow a contract to move certain assets without requiring a new signature for each transaction. In the case of the Payment Processor, the vulnerability made it possible to act on behalf of wallets that still held these permissions, even if users had canceled old listings. Revoke.cash

Magic Eden stated that no active listing on the platform was affected. According to the company, users who listed NFTs on its EVM marketplace roughly between February and October 2024 may be exposed. The Block

Attacks have already caused losses of at least US$ 2.8 million

The first known attack occurred on September 24, when more than 300 NFTs were withdrawn from a wallet. After the vulnerability became public, other actors began exploiting the same mechanism against NFTs, WETH and other tokens on different networks. Revoke.cash

Revoke.cash estimated at least US$ 2.8 million as the amount actually stolen on Ethereum, Polygon, Base, Arbitrum and ApeChain. The survey recorded about 580 WETH drained, in addition to USDC, POL and other assets. Revoke.cash

In parallel, an operation led by researcher 0xQuit, vice president of blockchain at Yuga Labs, used the vulnerability itself to transfer exposed assets to a custody wallet. According to him, 23,155 NFTs valued at more than US$ 5.7 million were rescued. Decrypt

Limit Break managed to pause more recent versions of the Payment Processor, but the V2 does not have a pause or upgrade mechanism, which prevents directly fixing the already deployed contract. Revoke.cash

Users who still hold approvals for the affected contracts remain exposed until they revoke them on-chain. Canceling an old listing, disconnecting the wallet from a site, or simply no longer using the marketplace does not eliminate these permissions. Magic Eden recommended revoking the approvals related to the Payment Processor on the affected networks. Decrypt

The owners of the NFTs transferred by the white-hat operation can already begin the process to recover the assets, conditioned on revoking the vulnerable permissions.

More from Radar