GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Attack ongoing, Yuga Labs VP reminds users to revoke PPV2-related approvals immediately

— According to Quit monitoring, the Payment Processor V2 (PPV2) exploit attack is still ongoing. Even if users were not affected in the September 25 incident, as long as they have not revoked the relevant approvals, their assets may still be at risk. Users are advised to revoke approvals immediately.About 1 hour ago, an address lost 0.15246 WETH in the next block after accepting a quote and receiving funds. The attacker paid 99% of it as a tip to Titan Builder and kept only about 0.0015 ETH, making it nearly impossible to rescue the funds through frontrunning.Quit suggests that OpenSea could check whether a user still has risky approvals before they accept a quote and require them to revoke them first; when transferring NFTs, it should also check whether the receiving address has any related approvals remaining.

Yuga Labs: Some Stolen ERC721C/1155C NFT Assets Temporarily Unable to Be Claimed

Yuga Labs blockchain vice president Quit posted on X that the asset claim website for NFTs stolen in the previous Payment Processor vulnerability incident has gone live. However, if an NFT collection uses the ERC721C or ERC1155C standard, its holders may temporarily be unable to claim assets through the NFT claim website. A number of NFT collections are currently affected by this issue. The relevant collections controlled by Yuga Labs are expected to be fixed by tomorrow. In the meantime, users can enable "7702 delegate OTC" in the transfer verifier settings, or add the specified Ethereum address and ApeChain address to the 7702 delegated address whitelist to remove the relevant restrictions.

Limit Break contract has a known vulnerability; Magic Eden Ethereum marketplace NFT traders need to revoke approvals

Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.

Quit: NFTs Are Safe Claim Portal Officially Launched, Affected Users Can Reclaim Preserved Assets

Yuga Labs blockchain vice president Quit posted on X that the NFT theft incident asset claim website nftsaresafu.xyz has officially launched. Affected users whose NFTs were successfully preserved can now proceed with claims, but must first revoke authorization to PaymentProcessor.Quit stated that approximately $6 million worth of NFTs were successfully rescued this time, but some assets could not be preserved. Additionally, some NFT collections cannot be claimed at present due to Transfer Validator restrictions, and coordination with the relevant project teams will be handled in the coming days. The claim process involves EIP-7702 delegated wallets, which may cause transaction simulation anomalies or risk warnings on wallets such as Rabby.

OpenSea: Unaffected by the Magic Eden security incident, has marked related NFTs and restricted trading

OpenSea Chief Technology Officer (CTO) Chris Maddern responded on X regarding the impact of the Magic Eden and Limit Break security incidents, emphasizing that OpenSea’s systems and smart contracts remain unaffected. All currently known affected ERC-721 NFTs have been flagged on OpenSea and are now unsellable; for any newly discovered exploited NFTs, OpenSea will automatically flag them to restrict attackers from securing related bids.

Yuga Labs Blockchain VP: NFT Theft Claims Portal Expected to Launch Within Hours, ETH and Other Token Donations Now Open

Yuga Labs Blockchain VP Quit posted on X that the NFT theft claims portal currently being built is expected to go live within the next few hours, and a dedicated address nftsaresafu.eth has been created to accept donations in ETH and other tokens.Quit stated that in addition to investing significant time, they paid approximately $7,500 in gas fees last night to handle related matters, and thanked the community for its support through channels such as X Money.Earlier reports indicated that NFT marketplace Magic Eden appears to have suffered an NFT security vulnerability, with white-hat hackers moving 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million.

Magic Eden responds to vulnerability issue: Discontinued Payment Processor V2 in October 2024; No impact on existing listings.

Magic Eden clarified on the X platform that Payment Processor V2, an NFT trading protocol under Limit Break, was recently exploited. Magic Eden stopped using this protocol in October 2024 and will completely shut down its EVM marketplace in Q1 2026, so this exploit did not affect existing Magic Eden listings. However, NFTs listed on the Magic Eden EVM marketplace from February to October 2024 may have been impacted, and users should revoke the "Approve for All" authorization for the contract on Ethereum, Polygon, and Base. Additionally, Magic Eden stated it is collaborating with Limit Break to investigate and seek further mitigation measures.

NFTs Worth Over $5.7 Million Protected in White Hat Rescue, Payment Processor Vulnerability Leads to Theft of NFTs Across Multiple Projects

Odaily reports: According to monitoring by Quit, at 9 AM EST today, an attacker exploited a vulnerability in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives. More than 12 hours after the incident, no one had reported it, and an investigation subsequently revealed that a large number of NFTs were facing the same risk. Quit stated that after contacting the LimitBreak team, they quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain was also temporarily in a state where it could not be paused, so the team carried out a white hat operation, transferring and protecting a total of 23,155 NFTs worth over $5.7 million. The team later discovered that the vulnerability could also be used in reverse to steal WETH, with approximately 660 WETH at risk, but these could not be recovered in time. Currently, all rescued NFTs have been transferred to secure addresses, and holders will be able to claim their assets in the future after revoking approvals for the vulnerable contracts.

Blockaid: Limit Break Faces Sustained Attacks, Approximately $1.7 Million in NFTs Stolen

Blockaid warns that users who previously authorized Payment Processor V2 as an NFT Operator should immediately revoke the relevant authorization. Simply canceling listings or Master Nonce cannot remove this permission.

Yuga Labs Blockchain Vice President Quit Reminds Users to Revoke Payment Processor V2 and V3 Approvals as Soon as Possible

Odaily News: According to monitoring by Quit, users should revoke their contract approvals for Ethereum Payment Processor V2 and ApeChain Payment Processor V3 as soon as possible, using revoke.cash or other similar tools. Quit stated that if a user's assets were transferred without authorization and are currently held at an address starting with 0x71cf, the relevant assets are in a safe state, but affected users still need to revoke the aforementioned contract approvals.Previously, NFT marketplace Magic Eden was suspected of having an NFT security vulnerability, with a white hat hacker transferring 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million. Quit stated that this transfer was a white hat operation, and the relevant NFTs are currently held at an address starting with 0x71cF and will all be returned once the risk is resolved.

Magic Eden Suspected of NFT Security Vulnerability as White-Hat Hacker Transfers 3,832 NFTs from Hundreds of Wallets

On-chain data shows that a single address received a total of 3,832 NFTs from hundreds of different wallets within a short period, sparking concerns among community members about a large-scale NFT theft incident.

Magic Eden appears to have an NFT security vulnerability, white hat hacker moves 3,832 NFTs from hundreds of wallets

according to monitoring, Magic Eden appears to have an NFT security vulnerability, with a white hat hacker moving 3,832 NFTs from hundreds of wallets.

North Korean hacker group WaterPlum poses as recruiters to steal over 7,000 crypto wallets worth $10.71 million

Odaily News: North Korean hacker group WaterPlum obtained funds or credentials from over 7,000 crypto wallets through fake recruitment processes and transferred approximately $10.71 million to North Korea. Between December 2025 and July 2026, the group infected at least 30,000 devices across more than 100 countries.WaterPlum impersonates AI, crypto, or NFT companies and approaches developers through social media, job platforms, and freelance platforms, luring them into downloading malware-laden files under the guise of technical interviews or coding assignments. Targets include web designers, engineers, and professionals in the crypto, blockchain, and Web3 sectors.Japanese law enforcement dismantled a "laptop farm" within the country for the first time, discovering that hundreds of millions of yen in crypto assets had already been transferred overseas. Investigations suggest that WaterPlum and some North Korean remote IT workers both belong to the 313th General Bureau of North Korea's Ministry of Munitions Industry and share IP addresses used to access the laptop farm and job-seeking services. (Decrypt)

North Korean Hacker Group WaterPlum Poses as Recruiters, Infects 30,000 Devices and Steals $10.7 Million in Crypto Assets

Odaily reports: The North Korean hacker group WaterPlum has been posing as recruiters for cryptocurrency, AI, and NFT companies, targeting software developers and IT professionals with malware disguised as coding assignments or video conferencing fix files.The group has infected at least 30,000 devices across more than 100 countries, and between December 2025 and July 2026, extracted funds or account credentials from over 7,000 cryptocurrency wallets, stealing at least $10.7 million. (Cointelegraph)

ZachXBT Slams zkSNARKs: Calls It an Ordinals Scam, Raised $17 Million With Zero Practical Utility

On-chain analyst ZachXBT (@zachxbt) disclosed that the recently launched 10K PFP NFT project zkSNARKs on the Zcash chain is allegedly a rug pull. The project attracted a total of 16,971 bids via a blind auction, ultimately completing the allocation of 8,000 items at a clearing price of 1.5 ZEC (approximately $2,190). Total trading volume reached 25,305 ZEC (approximately $36.94 million), and refunds totaling 13,309 ZEC (approximately $19.43 million) have been progressively returned. ZachXBT noted that the project raised approximately $17 million, while incorporating a 10% team allocation, 5% royalties, and a minting fee of around $2,000, yet offered zero utility. This mirrors the typical "rug pull" strategy commonly seen in Ordinals-style projects.

Fake GTA 6 Leak Website Can Steal Users' Crypto Wallet Assets

Malwarebytes researchers discovered a website disguised as a Grand Theft Auto VI (GTA 6) fan countdown page that lured users into purchasing the so-called leaked version of the game and loaded a wallet drainer program after users connected their cryptocurrency wallets. The malicious code checks wallet balances, identifies tokens and NFTs, and transfers assets once users approve transactions or grant authorizations.

UK National Crime Agency Freezes Millions in Sorare Assets

The UK National Crime Agency announced the freezing of assets belonging to NFT platform Sorare, seizing approximately £1 million in funds. The case involves cryptocurrency fraud and money laundering using proceeds from the Binance hack.

Operations Ceased, SecondFi Wallet Migration Tool Launches August 13, Affected Asset Recovery Portal Expected by September 10

: Cardano ecosystem wallet project SecondFi has announced the launch of a wallet migration tool and revealed a recovery plan for assets affected by the June 2026 security incident. As the project will cease operations, users are required to migrate remaining assets still held in SecondFi wallets. The migration tool is expected to go live on August 13, supporting the transfer of eligible ADA, Cardano native tokens, and NFTs to new Cardano wallets created with service providers of the users' choosing. Currently, the tool only supports Cardano network assets; non-Cardano assets must be transferred separately through corresponding network and wallet processes. SecondFi stated that the migration tool has passed an independent security assessment by security firm Bitdefender. For affected assets, SecondFi plans to launch a recovery portal before September 10, where users can verify wallet ownership via zero-knowledge proofs (ZK Proof) and submit asset claims. SecondFi reminds users to only rely on information published through official channels, including @secondfiapp, @secondfi_jp, and the official support website, to guard against phishing sites and impersonating accounts.

SlowMist Yu Xian: The Asterix attack resembles the Flooring Protocol’s approach.

SlowMist founder Yu Xian tweeted that, after preliminary analysis, the Asterix attack employed a method similar to yesterday’s Flooring Protocol incident. The underlying protocols involved are DN404 and BT404, respectively. The issue relates to integer overflow and reuse caused by high-value NFT ID bit-shift operations, suggesting the attacker may be searching for similar vulnerabilities.

Yuga Labs Completes White-Hat Action on Flooring Protocol and Temporarily Takes Control of Multiple High-Value NFTs

Yuga Labs tweeted that it has completed a white-hat operation targeting a newly discovered vulnerability in the Flooring Protocol and is temporarily safeguarding the rescued assets, including 29 Bored Apes, 4 Mutant Apes, 1 BAKC, 2 CryptoPunks, 1 Azuki, 2 Elementals, 26 Captains, 1 Moonbird, and 2 Doodles.