Magic is a wallet-as-a-service provider that helps businesses onboard users into web3 with instant non-custodial wallet creation. It uses email or social logins, while removing the need for seed phrases and browser extensions - making it indistinguishable from standard web2 experiences that everyday users are accustomed to. Magic offers features for end-to-end web3 onboarding including authentication, fiat onramps, NFT Minting and NFT Checkout.
Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.
Magic Eden clarified on the X platform that Payment Processor V2, an NFT trading protocol under Limit Break, was recently exploited. Magic Eden stopped using this protocol in October 2024 and will completely shut down its EVM marketplace in Q1 2026, so this exploit did not affect existing Magic Eden listings. However, NFTs listed on the Magic Eden EVM marketplace from February to October 2024 may have been impacted, and users should revoke the "Approve for All" authorization for the contract on Ethereum, Polygon, and Base. Additionally, Magic Eden stated it is collaborating with Limit Break to investigate and seek further mitigation measures.
Odaily Seer Channel monitoring shows that the probability of "Magic advancing to the NBA playoffs" on Polymarket has dropped to 39%, down 30% in 24 hours. Yesterday, the Magic lost to the 76ers with a score of 97 to 109 and will compete with the Hornets tomorrow morning at 7:30 for the final Eastern Conference playoff spot. Additionally, Hornets star LaMelo Ball was fined $35,000 for pulling Adebayo during the game against the Heat and was assessed a Flagrant Foul 2, but did not receive a suspension. Furthermore, Ball was fined $25,000 for using profanity in a post-game interview, resulting in a total fine of $60,000.Odaily Seer Channel continues to monitor prediction markets, seeing changes before they are priced in.
On-chain data shows that a single address received a total of 3,832 NFTs from hundreds of different wallets within a short period, sparking concerns among community members about a large-scale NFT theft incident.
According to on-chain analyst Ai Yi, Maji has lost $6.161 million over the past seven days, gained $4.202 million over the past 30 days, and incurred a cumulative account loss of $30.7 million. Currently, Maji still holds BTC and ETH long positions worth approximately $128 million. Of these, the 39,100 ETH long position shows an unrealized loss of $980,000, with a liquidation price of $2,342.78, approximately $60 away from the current price; the 440 BTC long position shows an unrealized profit of $175,000.
According to Odaily, blockchain analytics platform Bubblemaps has disclosed that a mysterious whale address cluster within the Shiba Inu (SHIB) ecosystem has held approximately 103 trillion SHIB since 2020. The entity initially spent just 38 ETH (roughly $10,000 at the time) to build the position, which once peaked at an unrealized valuation exceeding $50 billion, marking one of the most astonishing investment cases in crypto market history.Bubblemaps' tracking reveals that the whale initially purchased 103 trillion SHIB through the wallet address 0x1406, accounting for about 10% of the circulating supply at the time. As the SHIB price surged, the position's value once reached approximately $5 billion. Currently, the address cluster's holdings are still valued at over $2.5 billion, representing a cumulative return of more than 21,000 times.To reduce exposure risk, the whale split the assets across 14 addresses in November 2021. In January 2023, Bubblemaps first disclosed this SHIB whale cluster, which then controlled about 10% of the SHIB supply, valued at over $1 billion, sparking community discussions about high concentration of holdings by a single entity.Subsequently, the address cluster underwent continuous address migration and splitting. In September 2023, Bubblemaps found that its holdings had spread from a few prominent wallets to many new addresses, a typical tactic to reduce on-chain visibility. Using its Magic Nodes tool, Bubblemaps was still able to identify the connections between these wallets.During the SHIB price surge in early 2024, the whale's position value exceeded $2 billion again, with the number of wallets expanding to over 170 addresses. As of now, the cluster still controls approximately 8.51% of the SHIB circulating supply, a decrease from the initial 10% ratio. However, Bubblemaps notes that this is primarily due to normal on-chain transfers, with no signs of large-scale selling detected.Bubblemaps points out that this case highlights the significant value of on-chain transparency tools: an entity can conceal massive holdings by splitting wallets, but all fund transfers leave public on-chain records. This SHIB whale case has also become a typical example for observing "whale behavior, holding concentration, and on-chain tracking" within the crypto market.
Revoke.cash issued a reminder stating that, following last week's Magic Eden security incident, Ultimate subscribers must ensure their wallets meet two conditions for the Auto-Revoking feature to properly protect assets: first, granting Auto-Revoking permissions for the wallet in MetaMask; second, the wallet has been upgraded to a MetaMask Smart Account on the corresponding network. The second step is normally completed automatically during the authorization process, but if the address had already been upgraded to a Smart Account via another wallet application, the upgrade may fail.
The Abracadabra community is voting on a proposal for the orderly shutdown of the protocol and its stablecoin MIM (Magic Internet Money). The proposal notes that, affected by factors such as multiple previous hacking attacks, the protocol currently holds approximately $21 million in bad debt. With the circulating MIM supply nearing $22 million and recoverable collateral valued at only around $900,000, the effective asset reserve ratio has fallen below 4%, leaving no viable path to restore the peg.
Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.
OpenSea Chief Technology Officer (CTO) Chris Maddern responded on X regarding the impact of the Magic Eden and Limit Break security incidents, emphasizing that OpenSea’s systems and smart contracts remain unaffected. All currently known affected ERC-721 NFTs have been flagged on OpenSea and are now unsellable; for any newly discovered exploited NFTs, OpenSea will automatically flag them to restrict attackers from securing related bids.
Yuga Labs Blockchain VP Quit posted on X that the NFT theft claims portal currently being built is expected to go live within the next few hours, and a dedicated address nftsaresafu.eth has been created to accept donations in ETH and other tokens.Quit stated that in addition to investing significant time, they paid approximately $7,500 in gas fees last night to handle related matters, and thanked the community for its support through channels such as X Money.Earlier reports indicated that NFT marketplace Magic Eden appears to have suffered an NFT security vulnerability, with white-hat hackers moving 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million.
Odaily News: Magic Eden co-founder Jack posted on X platform that Magic Eden was not attacked today. This incident involves Limit Break's transaction protocol and smart contracts, which Magic Eden stopped using two years ago. The team is currently discussing further measures with Limit Break, including pushing for a pause on asset transfers at the protocol level; until then, users should follow official guidance to revoke relevant authorizations on Magic Eden. Jack also thanked white-hat hacker 0xQuit for participating in the rescue and said more updates will be announced later.
Revoke.cash issued a reminder stating that, following last week's Magic Eden security incident, Ultimate subscribers must ensure their wallets meet two conditions for the Auto-Revoking feature to properly protect assets: first, granting Auto-Revoking permissions for the wallet in MetaMask; second, the wallet has been upgraded to a MetaMask Smart Account on the corresponding network. The second step is normally completed automatically during the authorization process, but if the address had already been upgraded to a Smart Account via another wallet application, the upgrade may fail.
Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.
Yuga Labs Blockchain VP Quit posted on X that the NFT theft claims portal currently being built is expected to go live within the next few hours, and a dedicated address nftsaresafu.eth has been created to accept donations in ETH and other tokens.Quit stated that in addition to investing significant time, they paid approximately $7,500 in gas fees last night to handle related matters, and thanked the community for its support through channels such as X Money.Earlier reports indicated that NFT marketplace Magic Eden appears to have suffered an NFT security vulnerability, with white-hat hackers moving 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million.
Revoke.cash issued a reminder stating that, following last week's Magic Eden security incident, Ultimate subscribers must ensure their wallets meet two conditions for the Auto-Revoking feature to properly protect assets: first, granting Auto-Revoking permissions for the wallet in MetaMask; second, the wallet has been upgraded to a MetaMask Smart Account on the corresponding network. The second step is normally completed automatically during the authorization process, but if the address had already been upgraded to a Smart Account via another wallet application, the upgrade may fail.
Odaily reports: A judge in the US District Court for the Eastern District of New York has dismissed a class action lawsuit over the ME token against Euclid Labs, the operating entity behind Magic Eden, and its co-founder Zhuoxun Yin. The plaintiffs alleged that the platform had promoted the ME token as offering cross-chain capabilities and buyback benefits, but later pivoted to a gambling platform, causing the token price to fall by more than 98%.The judge determined that the wallet terms signed by users contained a valid class action waiver, and the federal court therefore lacked subject matter jurisdiction under the Class Action Fairness Act; the court also ruled that it lacked personal jurisdiction over Zhuoxun Yin. The ruling applies only to the pleading stage, and other defendants, including CEO Jack Lu, remain in the lawsuit.
The Abracadabra community is voting on a proposal for the orderly shutdown of the protocol and its stablecoin MIM (Magic Internet Money). The proposal notes that, affected by factors such as multiple previous hacking attacks, the protocol currently holds approximately $21 million in bad debt. With the circulating MIM supply nearing $22 million and recoverable collateral valued at only around $900,000, the effective asset reserve ratio has fallen below 4%, leaving no viable path to restore the peg.
Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.
OpenSea Chief Technology Officer (CTO) Chris Maddern responded on X regarding the impact of the Magic Eden and Limit Break security incidents, emphasizing that OpenSea’s systems and smart contracts remain unaffected. All currently known affected ERC-721 NFTs have been flagged on OpenSea and are now unsellable; for any newly discovered exploited NFTs, OpenSea will automatically flag them to restrict attackers from securing related bids.
Yuga Labs Blockchain VP Quit posted on X that the NFT theft claims portal currently being built is expected to go live within the next few hours, and a dedicated address nftsaresafu.eth has been created to accept donations in ETH and other tokens.Quit stated that in addition to investing significant time, they paid approximately $7,500 in gas fees last night to handle related matters, and thanked the community for its support through channels such as X Money.Earlier reports indicated that NFT marketplace Magic Eden appears to have suffered an NFT security vulnerability, with white-hat hackers moving 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million.