Magic Eden legacy contract flaw exposed $5.7M in NFTs before rescue
Security & Exploits ·
A vulnerability tied to old Ethereum listing approvals left millions of dollars in NFTs vulnerable to unauthorized transfer before whitehat intervention limited the damage.
Magic Eden NFTs worth $5.7 million were exposed to potential theft through legacy EVM approvals granted to Limit Break's Payment Processor V2, according to The Block. The exposure stemmed from old Ethereum marketplace listings that had never revoked their approvals, leaving holdings vulnerable even after users stopped actively using the affected listing mechanism.
The underlying issue was a contract vulnerability that allowed unauthorized NFT transfers from wallets that still carried the outdated approvals, as described by Decrypt. Once the flaw was identified, a whitehat actor moved at-risk NFTs out of affected wallets into secure custody to prevent them from being drained by anyone else who might have discovered the same weakness.
That intervention recovered 3,832 NFTs valued at roughly $1.5 million, a subset of the total $5.7 million initially exposed. Separate reporting on the incident, including from WuBlockchain, described the same rescue figure of 3,832 NFTs moved to secure wallets pending resolution, while other accounts in the cluster put total recovered listings above 23,000 NFTs across the marketplace's Ethereum operations.
A Yuga Labs-affiliated individual was reported to be exploring further whitehat recovery options for affected holders, suggesting the response effort extended beyond the initial rescue transaction. The discrepancy between the $5.7 million total exposure and the $1.5 million secured in the primary rescue action indicates that not all at-risk assets were necessarily moved to safety in a single operation.
What remains unclear is whether all NFTs tied to the vulnerable legacy approvals have now been secured, whether any assets were transferred by parties other than the whitehat before the rescue, and what remediation Magic Eden has implemented to prevent similar exposure from outdated contract approvals going forward. The full scope of affected wallets and any compensation or return process for holders has not been detailed.