nftvia Decrypt

Magic Eden Warns Old Ethereum NFT Listings at Risk from Payment Processor Exploit

Magic Eden alerted users that old Ethereum NFT listings were vulnerable to an exploit in Limit Break's Payment Processor V2. Whitehat hackers rescued over 23,000 NFTs, valued at $5.7 million, before any were stolen. Users are urged to revoke NFT permissions to stay safe.

Key takeaways

  • A flaw in Limit Break's Payment Processor V2 exposed old Magic Eden Ethereum NFT listings to an exploit.
  • Whitehat hackers rescued 23,155 NFTs valued at $5.7 million before any were stolen.
  • Yuga Labs' 0xQuit confirmed the NFTs are safe and will be returned once the risk passes.
  • Users are urged to revoke unnecessary NFT permissions to protect their assets.
Magic Eden Warns Old Ethereum NFT Listings at Risk from Payment Processor Exploit

Magic Eden has warned users that old Ethereum NFT listings on its platform were exposed to a critical exploit due to a flaw in Limit Break's Payment Processor V2. The vulnerability put thousands of NFTs at risk, prompting a whitehat rescue operation that saved 23,155 tokens valued at approximately $5.7 million. Users are now being urged to revoke any unnecessary permissions to protect their assets.

What Happened?

A flaw in the Payment Processor V2, developed by Limit Break, allowed potential attackers to exploit old NFT listings on Magic Eden. The vulnerability was discovered before any NFTs were stolen, thanks to the intervention of whitehat hackers. These ethical hackers took custody of 23,155 NFTs to prevent them from being compromised. The total value of the rescued NFTs is estimated at $5.7 million, according to The Block. CoinTelegraph reported that Yuga Labs' 0xQuit confirmed the NFTs are safe and will be returned once the risk passes, while holders were urged to revoke NFT permissions.

What Should NFT Holders Do?

Magic Eden and Yuga Labs' 0xQuit have advised all users to revoke any unnecessary permissions granted to their NFTs. This step is crucial to prevent potential exploits. The rescued NFTs will be returned to their rightful owners once the risk has been fully mitigated. For those unfamiliar with the process, revoking permissions typically involves interacting with a permission management tool on platforms like Etherscan.

Why This Matters

This incident highlights the ongoing risks associated with legacy approvals and the importance of regularly reviewing and revoking unnecessary permissions. It also underscores the value of whitehat hackers in the crypto community, who often step in to prevent exploits before they can cause significant damage. This is not the first time such a rescue operation has taken place, as seen in a similar incident involving Yuga Labs earlier this year Yuga Labs Rescues 60 NFTs After Exploit.

Frequently asked questions

What is a whitehat hacker?

A whitehat hacker is an ethical hacker who uses their skills to identify and fix vulnerabilities in systems, often preventing exploits before they can cause harm.

How can I revoke NFT permissions?

You can revoke NFT permissions by using a permission management tool on platforms like Etherscan. This process typically involves interacting with the smart contract associated with your NFT.

What should I do if my NFT was part of the rescue?

If your NFT was part of the rescue, you don't need to take any immediate action. The rescued NFTs will be returned to their rightful owners once the risk has been fully mitigated.

Why is it important to revoke unnecessary permissions?

Revoking unnecessary permissions reduces the risk of your NFTs being exploited. Unnecessary permissions can be targeted by attackers to steal or manipulate your assets.

#nft#ethereum#exploit#magic-eden#whitehat#security