GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Yuga Labs Vice President: PPv2 Exploit Ongoing, Urges Users to Revoke Token Approvals Immediately

Yuga Labs Blockchain Vice President Quit (0xQuit) warns that the security vulnerability associated with PPv2 remains actively exploited, leaving even previously unaffected users at risk. Monitoring shows that an address was drained within a single block after accepting a quote and receiving 0.15246 WETH; attackers directed 99% of the illicit proceeds to block builders (Titan Builder), making conventional fund recovery via frontrunning extremely difficult.

Attack ongoing, Yuga Labs VP reminds users to revoke PPV2-related approvals immediately

— According to Quit monitoring, the Payment Processor V2 (PPV2) exploit attack is still ongoing. Even if users were not affected in the September 25 incident, as long as they have not revoked the relevant approvals, their assets may still be at risk. Users are advised to revoke approvals immediately.About 1 hour ago, an address lost 0.15246 WETH in the next block after accepting a quote and receiving funds. The attacker paid 99% of it as a tip to Titan Builder and kept only about 0.0015 ETH, making it nearly impossible to rescue the funds through frontrunning.Quit suggests that OpenSea could check whether a user still has risky approvals before they accept a quote and require them to revoke them first; when transferring NFTs, it should also check whether the receiving address has any related approvals remaining.

Yuga Labs: Some Stolen ERC721C/1155C NFT Assets Temporarily Unable to Be Claimed

Yuga Labs blockchain vice president Quit posted on X that the asset claim website for NFTs stolen in the previous Payment Processor vulnerability incident has gone live. However, if an NFT collection uses the ERC721C or ERC1155C standard, its holders may temporarily be unable to claim assets through the NFT claim website. A number of NFT collections are currently affected by this issue. The relevant collections controlled by Yuga Labs are expected to be fixed by tomorrow. In the meantime, users can enable "7702 delegate OTC" in the transfer verifier settings, or add the specified Ethereum address and ApeChain address to the 7702 delegated address whitelist to remove the relevant restrictions.

Limit Break contract has a known vulnerability; Magic Eden Ethereum marketplace NFT traders need to revoke approvals

Odaily report: According to RevokeCash monitoring, if users have previously traded NFTs on the Magic Eden Ethereum marketplace, their wallets may have granted approval to Limit Break's Payment Processor contract; this contract currently has a known vulnerability, and it is recommended to revoke the approval. Magic Eden previously stated that NFTs currently still listed on its platform are not affected by this vulnerability; NFTs listed through its EVM marketplace between approximately February 2024 and October 2024 may be affected, while listings after October 2024 are in principle not affected. Magic Eden is contacting protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and continues to investigate the actual scope of impact.Users who have previously listed or traded NFTs on the Magic Eden EVM marketplace should revoke the relevant contract approvals on Ethereum, Polygon, and Base networks, and revoke all NFT approvals marked as "approved for all." Yuga Labs Blockchain Vice President Quit stated that the asset claim website for the Payment Processor vulnerability NFT theft incident has officially launched; affected users whose NFTs were successfully safeguarded can now claim, but must first revoke their approval to the Payment Processor.

Quit: NFTs Are Safe Claim Portal Officially Launched, Affected Users Can Reclaim Preserved Assets

Yuga Labs blockchain vice president Quit posted on X that the NFT theft incident asset claim website nftsaresafu.xyz has officially launched. Affected users whose NFTs were successfully preserved can now proceed with claims, but must first revoke authorization to PaymentProcessor.Quit stated that approximately $6 million worth of NFTs were successfully rescued this time, but some assets could not be preserved. Additionally, some NFT collections cannot be claimed at present due to Transfer Validator restrictions, and coordination with the relevant project teams will be handled in the coming days. The claim process involves EIP-7702 delegated wallets, which may cause transaction simulation anomalies or risk warnings on wallets such as Rabby.

Yuga Labs Blockchain VP: NFT Theft Claims Portal Expected to Launch Within Hours, ETH and Other Token Donations Now Open

Yuga Labs Blockchain VP Quit posted on X that the NFT theft claims portal currently being built is expected to go live within the next few hours, and a dedicated address nftsaresafu.eth has been created to accept donations in ETH and other tokens.Quit stated that in addition to investing significant time, they paid approximately $7,500 in gas fees last night to handle related matters, and thanked the community for its support through channels such as X Money.Earlier reports indicated that NFT marketplace Magic Eden appears to have suffered an NFT security vulnerability, with white-hat hackers moving 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million.

Yuga Labs Blockchain Vice President Quit Reminds Users to Revoke Payment Processor V2 and V3 Approvals as Soon as Possible

Odaily News: According to monitoring by Quit, users should revoke their contract approvals for Ethereum Payment Processor V2 and ApeChain Payment Processor V3 as soon as possible, using revoke.cash or other similar tools. Quit stated that if a user's assets were transferred without authorization and are currently held at an address starting with 0x71cf, the relevant assets are in a safe state, but affected users still need to revoke the aforementioned contract approvals.Previously, NFT marketplace Magic Eden was suspected of having an NFT security vulnerability, with a white hat hacker transferring 3,832 NFTs from hundreds of wallets, worth approximately $1.5 million. Quit stated that this transfer was a white hat operation, and the relevant NFTs are currently held at an address starting with 0x71cF and will all be returned once the risk is resolved.

Yuga Labs Completes White-Hat Action on Flooring Protocol and Temporarily Takes Control of Multiple High-Value NFTs

Yuga Labs tweeted that it has completed a white-hat operation targeting a newly discovered vulnerability in the Flooring Protocol and is temporarily safeguarding the rescued assets, including 29 Bored Apes, 4 Mutant Apes, 1 BAKC, 2 CryptoPunks, 1 Azuki, 2 Elementals, 26 Captains, 1 Moonbird, and 2 Doodles.