Magic Eden Suspected of NFT Security Vulnerability as White Hat Moves 3,832 NFTs
Magic Eden Suspected of NFT Security Vulnerability as White Hat Moves 3,832 NFTs
NFT marketplace Magic Eden is suspected of having a security vulnerability after a white hat moved 3,832 NFTs from hundreds of wallets. Yuga Labs CEO Michael Figge said the issue was discovered hours earlier and that Yuga Labs VP of Blockchain Quit (0xQuit) is handling affected assets within the scope of the white-hat rescue. Quit said the NFTs are currently secured at an address beginning with 0x71cF and will be returned to their original owners once the risk is resolved. Magic Eden has not yet disclosed the cause or full scope of the issue.
Yuga Labs VP of Blockchain Quit (0xQuit) said the NFT security incident initially suspected to involve Magic Eden was actually caused by a vulnerability in Limit Break Payment Processor V2. The team then launched a white-hat rescue, securing 23,155 NFTs worth more than $5.7 million, all of which have now been safely relocated. Quit added that a similar exploit could also be used to steal WETH, with about 660 WETH not recovered in time. Payment Processor V3 on ApeChain is also affected by a similar issue. Quit published the Payment Processor V2 contract on Ethereum and the V3 contract on ApeChain that users should revoke, and recommended using tools such as revoke.cash to remove the relevant approvals.
Magic Eden said it stopped using Payment Processor V2 in October 2024 and shut down its EVM Marketplace in Q1 2026, so no current live listings were affected by the incident. The company said NFTs listed on its EVM marketplace between approximately February and October 2024 may have been affected, while listings made after October 2024 are not expected to be impacted. Magic Eden is continuing its investigation and is working with Limit Break on additional mitigation measures. — link
Post #56646
254