GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Revoke.cash Notice: Ultimate subscription users need to check Auto-Revoking settings.

Revoke.cash issued a reminder stating that, following last week's Magic Eden security incident, Ultimate subscribers must ensure their wallets meet two conditions for the Auto-Revoking feature to properly protect assets: first, granting Auto-Revoking permissions for the wallet in MetaMask; second, the wallet has been upgraded to a MetaMask Smart Account on the corresponding network. The second step is normally completed automatically during the authorization process, but if the address had already been upgraded to a Smart Account via another wallet application, the upgrade may fail.

Limit Break contract has a known vulnerability; Magic Eden Ethereum marketplace NFT traders need to revoke approvals

Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.

OpenSea: Unaffected by the Magic Eden security incident, has marked related NFTs and restricted trading

OpenSea Chief Technology Officer (CTO) Chris Maddern responded on X regarding the impact of the Magic Eden and Limit Break security incidents, emphasizing that OpenSea’s systems and smart contracts remain unaffected. All currently known affected ERC-721 NFTs have been flagged on OpenSea and are now unsellable; for any newly discovered exploited NFTs, OpenSea will automatically flag them to restrict attackers from securing related bids.

Yuga Labs Blockchain VP: NFT Theft Claims Portal Expected to Launch Within Hours, ETH and Other Token Donations Now Open

Yuga Labs Blockchain VP Quit posted on X that the NFT theft claims portal currently being built is expected to go live within the next few hours, and a dedicated address nftsaresafu.eth has been created to accept donations in ETH and other tokens.Quit stated that in addition to investing significant time, they paid approximately $7,500 in gas fees last night to handle related matters, and thanked the community for its support through channels such as X Money.Earlier reports indicated that NFT marketplace Magic Eden appears to have suffered an NFT security vulnerability, with white-hat hackers moving 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million.

Magic Eden co-founder: Platform was not attacked, vulnerability involves Limit Break transaction protocol

Odaily News: Magic Eden co-founder Jack posted on X platform that Magic Eden was not attacked today. This incident involves Limit Break's transaction protocol and smart contracts, which Magic Eden stopped using two years ago. The team is currently discussing further measures with Limit Break, including pushing for a pause on asset transfers at the protocol level; until then, users should follow official guidance to revoke relevant authorizations on Magic Eden. Jack also thanked white-hat hacker 0xQuit for participating in the rescue and said more updates will be announced later.

Magic Eden responds to vulnerability issue: Discontinued Payment Processor V2 in October 2024; No impact on existing listings.

Magic Eden clarified on the X platform that Payment Processor V2, an NFT trading protocol under Limit Break, was recently exploited. Magic Eden stopped using this protocol in October 2024 and will completely shut down its EVM marketplace in Q1 2026, so this exploit did not affect existing Magic Eden listings. However, NFTs listed on the Magic Eden EVM marketplace from February to October 2024 may have been impacted, and users should revoke the "Approve for All" authorization for the contract on Ethereum, Polygon, and Base. Additionally, Magic Eden stated it is collaborating with Limit Break to investigate and seek further mitigation measures.

Yuga Labs Blockchain Vice President Quit Reminds Users to Revoke Payment Processor V2 and V3 Approvals as Soon as Possible

Odaily News: According to monitoring by Quit, users should revoke their contract approvals for Ethereum Payment Processor V2 and ApeChain Payment Processor V3 as soon as possible, using revoke.cash or other similar tools. Quit stated that if a user's assets were transferred without authorization and are currently held at an address starting with 0x71cf, the relevant assets are in a safe state, but affected users still need to revoke the aforementioned contract approvals.Previously, NFT marketplace Magic Eden was suspected of having an NFT security vulnerability, with a white hat hacker transferring 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million. Quit stated that this transfer was a white hat operation, and the relevant NFTs are currently held at an address starting with 0x71cF and will all be returned once the risk is resolved.

Magic Eden Suspected of NFT Security Vulnerability as White-Hat Hacker Transfers 3,832 NFTs from Hundreds of Wallets

On-chain data shows that a single address received a total of 3,832 NFTs from hundreds of different wallets within a short period, sparking concerns among community members about a large-scale NFT theft incident.

Magic Eden appears to have an NFT security vulnerability, white hat hacker moves 3,832 NFTs from hundreds of wallets

according to monitoring, Magic Eden appears to have an NFT security vulnerability, with a white hat hacker moving 3,832 NFTs from hundreds of wallets.