News linked to both this project and an event.
Revoke.cash issued a reminder stating that, following last week's Magic Eden security incident, Ultimate subscribers must ensure their wallets meet two conditions for the Auto-Revoking feature to properly protect assets: first, granting Auto-Revoking permissions for the wallet in MetaMask; second, the wallet has been upgraded to a MetaMask Smart Account on the corresponding network. The second step is normally completed automatically during the authorization process, but if the address had already been upgraded to a Smart Account via another wallet application, the upgrade may fail.
The Abracadabra community is voting on a proposal for the orderly shutdown of the protocol and its stablecoin MIM (Magic Internet Money). The proposal notes that, affected by factors such as multiple previous hacking attacks, the protocol currently holds approximately $21 million in bad debt. With the circulating MIM supply nearing $22 million and recoverable collateral valued at only around $900,000, the effective asset reserve ratio has fallen below 4%, leaving no viable path to restore the peg.
Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.
OpenSea Chief Technology Officer (CTO) Chris Maddern responded on X regarding the impact of the Magic Eden and Limit Break security incidents, emphasizing that OpenSea’s systems and smart contracts remain unaffected. All currently known affected ERC-721 NFTs have been flagged on OpenSea and are now unsellable; for any newly discovered exploited NFTs, OpenSea will automatically flag them to restrict attackers from securing related bids.
Yuga Labs Blockchain VP Quit posted on X that the NFT theft claims portal currently being built is expected to go live within the next few hours, and a dedicated address nftsaresafu.eth has been created to accept donations in ETH and other tokens.Quit stated that in addition to investing significant time, they paid approximately $7,500 in gas fees last night to handle related matters, and thanked the community for its support through channels such as X Money.Earlier reports indicated that NFT marketplace Magic Eden appears to have suffered an NFT security vulnerability, with white-hat hackers moving 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million.
Odaily News: Magic Eden co-founder Jack posted on X platform that Magic Eden was not attacked today. This incident involves Limit Break's transaction protocol and smart contracts, which Magic Eden stopped using two years ago. The team is currently discussing further measures with Limit Break, including pushing for a pause on asset transfers at the protocol level; until then, users should follow official guidance to revoke relevant authorizations on Magic Eden. Jack also thanked white-hat hacker 0xQuit for participating in the rescue and said more updates will be announced later.
Magic Eden clarified on the X platform that Payment Processor V2, an NFT trading protocol under Limit Break, was recently exploited. Magic Eden stopped using this protocol in October 2024 and will completely shut down its EVM marketplace in Q1 2026, so this exploit did not affect existing Magic Eden listings. However, NFTs listed on the Magic Eden EVM marketplace from February to October 2024 may have been impacted, and users should revoke the "Approve for All" authorization for the contract on Ethereum, Polygon, and Base. Additionally, Magic Eden stated it is collaborating with Limit Break to investigate and seek further mitigation measures.
Odaily News: According to monitoring by Quit, users should revoke their contract approvals for Ethereum Payment Processor V2 and ApeChain Payment Processor V3 as soon as possible, using revoke.cash or other similar tools. Quit stated that if a user's assets were transferred without authorization and are currently held at an address starting with 0x71cf, the relevant assets are in a safe state, but affected users still need to revoke the aforementioned contract approvals.Previously, NFT marketplace Magic Eden was suspected of having an NFT security vulnerability, with a white hat hacker transferring 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million. Quit stated that this transfer was a white hat operation, and the relevant NFTs are currently held at an address starting with 0x71cF and will all be returned once the risk is resolved.
On-chain data shows that a single address received a total of 3,832 NFTs from hundreds of different wallets within a short period, sparking concerns among community members about a large-scale NFT theft incident.
according to monitoring, Magic Eden appears to have an NFT security vulnerability, with a white hat hacker moving 3,832 NFTs from hundreds of wallets.