Old Magic Eden NFT approvals put users at risk after whitehat moves 3,832 NFTs
Old Magic Eden NFT approvals may nonetheless put some former users at risk months after the corporate closed its Ethereum market. A September 25 warning from pockets safety service Revoke.money says {that a} vulnerability in Limit Break’s Payment Processor V2 impacts wallets that also authorize the contract to maneuver NFTs. Those approvals stay energetic till homeowners revoke them.
The discover says safety researcher 0xQuit used the vulnerability to maneuver 3,832 NFTs from authorized wallets as zero ETH gross sales. He described the transfers as a whitehat rescue and stated the belongings had been being held in a custody pockets till it was secure to return them, based on Revoke.money. The determine counts transfers reported within the discover; the service had not established what number of NFTs, if any, malicious actors took.
Magic Eden ended EVM marketplace support on March 9, 2026. Its listings and presents had been offchain and ceased to be seen or actionable on the location. The operator approval users gave the processor exists onchain, nevertheless. Closing {the marketplace} didn’t cancel that separate permission, leaving individuals who haven’t traded there for months with a dwell publicity.
Which Magic Eden NFT approvals ought to users revoke?
Revoke.money says users ought to revoke Payment Processor V2 approval on Ethereum. It additionally warns anybody who authorized Payment Processor V3 on ApeChain to revoke that separate permission. An NFT operator approval lets a contract transfer belongings on a pockets’s behalf. A permission granted for market buying and selling can outlast the itemizing that prompted it, so former users have to examine the approval itself somewhat than their outdated sale historical past.
Canceling an inventory won’t shield an uncovered pockets, Revoke.money stated. Its FAQ additionally explains that disconnecting a pockets from a web site leaves onchain approvals energetic. The incident web page consists of an exploit checker so users can examine whether or not their tackle is affected and revoke the related permission. The warning applies to the named processor approvals; it doesn’t set up that losses occurred on each Ethereum and ApeChain. Revocation is a preventive step, the FAQ says: it reduces future publicity however doesn’t retrieve belongings already taken. That distinction makes checking outdated permissions pressing even whereas the complete incident consequence stays unknown.
The technical particulars of the flaw had not been revealed in Revoke.money’s September 25 discover, and the service stated it remained unclear whether or not malicious actors had taken any NFTs. The reported rescue leaves the ultimate loss determine unresolved. For holders with lingering approvals, the motion recognized within the warning is to revoke entry to the affected processor contracts.
The publish Old Magic Eden NFT approvals put users at risk after whitehat moves 3,832 NFTs appeared first on CryptoSlate.
