Magic Eden security vulnerability discovered in Payment Processor contracts on Ethereum and ApeChain; users advised to revoke approvals immediately.
Security & Exploits ·
A security vulnerability in Magic Eden's Payment Processor contracts on Ethereum and ApeChain prompted an immediate advisory on September 25. Users were directed to revoke approvals to Payment Processor V2 on Ethereum (0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834) and Payment Processor V3 on ApeChain (0x9a1D00000000fC540e2000560054812452eB5366) using tools like revoke.cash.
The vulnerability is being handled as a whitehat operation. A follow-up post clarified that any assets moved without permission to address 0x71cf3f5724bd2b72ef6464992acd26216de7fe33 would be returned once the risk subsides, and that approvals to the affected contracts should still be revoked as a precaution.
No details have been disclosed about the nature of the vulnerability, the scope of affected users, or a timeline for full resolution. The whitehat status indicates active coordination with the team, though the specifics of the exploit remain undisclosed.