Old Magic Eden NFT approvals put users at risk after whitehat moves 3,832 NFTs

요약:Magic Eden NFT approvals remain risky after a Limit Break flaw. Users should check and revoke old processor permissions on Ethereum or ApeChain.

Old Magic Eden NFT approvals could still put some former users at risk months after the company closed its Ethereum marketplace. A September 25 warning from wallet security service Revoke.cash says that a vulnerability in Limit Break's Payment Processor V2 affects wallets that still authorize the contract to move NFTs. Those approvals remain active until owners revoke them.

The notice says security researcher 0xQuit used the vulnerability to move 3,832 NFTs from approved wallets as zero ETH sales. He described the transfers as a whitehat rescue and said the assets were being held in a custody wallet until it was safe to return them, according to Revoke.cash. The figure counts transfers reported in the notice; the service had not established how many NFTs, if any, malicious actors took.

Magic Eden ended EVM marketplace support on March 9, 2026. Its listings and offers were offchain and ceased to be visible or actionable on the site. The operator approval users gave the processor exists onchain, however. Closing the marketplace did not cancel that separate permission, leaving people who have not traded there for months with a live exposure.

Related Company Magic Eden Multi-chain NFT marketplace

Which Magic Eden NFT approvals should users revoke?

Revoke.cash says users should revoke Payment Processor V2 approval on Ethereum. It also warns anyone who approved Payment Processor V3 on ApeChain to revoke that separate permission. An NFT operator approval lets a contract move assets on a wallet's behalf. A permission granted for marketplace trading can outlast the listing that prompted it, so former users need to check the approval itself rather than their old sale history.

Related Asset Ethereum ETH · $2,682.56 24-hour change: up 0.58%

Canceling a listing will not protect an exposed wallet, Revoke.cash said. Its FAQ also explains that disconnecting a wallet from a website leaves onchain approvals active. The incident page includes an exploit checker so users can inspect whether their address is affected and revoke the relevant permission. The warning applies to the named processor approvals; it does not establish that losses occurred on both Ethereum and ApeChain. Revocation is a preventive step, the FAQ says: it reduces future exposure but does not retrieve assets already taken. That distinction makes checking old permissions urgent even while the full incident outcome remains unknown.

The technical details of the flaw had not been published in Revoke.cash's September 25 notice, and the service said it remained unclear whether malicious actors had taken any NFTs. The reported rescue leaves the final loss figure unresolved. For holders with lingering approvals, the action identified in the warning is to revoke access to the affected processor contracts.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

사무라이 월렛 공동 창립자, 30일간의 수감 생활 후 이송에 직면

다음

10년물 국채 수익률이 19년 만에 최고치를 기록하면서 비트코인 8만4,000달러 아래로 하락