Old Magic Eden NFT approvals put users at risk after whitehat moves 3,832 NFTs
Old Magic Eden NFT approvals could still put some former users at risk months after the company closed its Ethereum marketplace. A September 25 warning from wallet security service Revoke.cash says that a vulnerability i...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Old Magic Eden NFT approvals could still put some former users at risk months after the company closed its Ethereum marketplace. A September 25 warning from wallet security service Revoke.cash says that a vulnerability in Limit Break's Payment Processor V2 affects wallets that still authorize the contract to move NFTs. Those approvals remain active until owners revoke them.
The notice says security researcher 0xQuit used the vulnerability to move 3,832 NFTs from approved wallets as zero ETH sales. He described the transfers as a whitehat rescue and said the assets were being held in a custody wallet until it was safe to return them, according to Revoke.cash. The figure counts transfers reported in the notice; the service had not established how many NFTs, if any, malicious actors took.
Related Reading White hats recover 52 Bitcoin from Coldcard exploit, and a new public portal lets victims check eligibilityMagic Eden ended EVM marketplace support on March 9, 2026. Its listings and offers were offchain and ceased to be visible or actionable on the site. The operator approval users gave the processor exists onchain, however. Closing the marketplace did not cancel that separate permission, leaving people who have not traded there for months with a live exposure.
Related Reading Ethereum's Jaredfromsubway MEV bot drained after approving its own $7.5M theft Which Magic Eden NFT approvals should users revoke?Revoke.cash says users should revoke Payment Processor V2 approval on Ethereum. It also warns anyone who approved Payment Processor V3 on ApeChain to revoke that separate permission. An NFT operator approval lets a contract move assets on a wallet's behalf. A permission granted for marketplace trading can outlast the listing that prompted it, so former users need to check the approval itself rather than their old sale history.
Canceling a listing will not protect an exposed wallet, Revoke.cash said. Its FAQ also explains that disconnecting a wallet from a website leaves onchain approvals active. The incident page includes an exploit checker so users can inspect whether their address is affected and revoke the relevant permission. The warning applies to the named processor approvals; it does not establish that losses occurred on both Ethereum and ApeChain. Revocation is a preventive step, the FAQ says: it reduces future exposure but does not retrieve assets already taken. That distinction makes checking old permissions urgent even while the full incident outcome remains unknown.
The technical details of the flaw had not been published in Revoke.cash's September 25 notice, and the service said it remained unclear whether malicious actors had taken any NFTs. The reported rescue leaves the final loss figure unresolved. For holders with lingering approvals, the action identified in the warning is to revoke access to the affected processor contracts.
The post Old Magic Eden NFT approvals put users at risk after whitehat moves 3,832 NFTs appeared first on CryptoSlate.
Why this matters
Ethereum is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
Trust Wallet integrates MoonPay so US users can buy crypto without leaving the app
The integration enhances user convenience and self-custody appeal but raises concerns about dependency on a single provider's stab...
Why Abstract is killing its Ethereum L2 instead of launching a token to save it
Abstract will shut down on Dec. 15 despite onboarding more than 400,000 users, hosting 144 apps, and landing brands including Disn...
Non-Custodial Crypto Exchanges: How Self-Custody Is Changing the Way Users Swap Digital Assets
For many users, the distinction comes down to custody. A centralized platform may hold assets on behalf of its customers, while a...
Ethereum Foundation researcher Justin Drake urges crypto to prepare ‘bunker mode’ for AI threats
AI advancements could accelerate blockchain vulnerabilities, urging the crypto industry to prioritize security measures and proact...
Tether Celebrates 12 Years, USD₮ Surpasses 700M Users
Key Takeaways: Tether marked the 12th anniversary of the world’s largest stablecoin by market cap, USD₮. The company claims that U...
Crypto Long & Short: Zcash and the case for privacy in the age of AI
AI has made it cheap to link wallet addresses to the people behind them, and the permanence of the blockchain means records don’t...