A vulnerability in Magic Eden's old EVM NFT marketplace contracts left hundreds of wallets exposed on September 25, six months after the platform shut down its Ethereum marketplace entirely. A security researcher moved 3,832 NFTs, worth over $1.5 million, into a single address to protect them before an attacker could exploit the same flaw.

How old approvals became a live risk months later

Magic Eden announced the shutdown of its EVM NFT marketplace in February, with the interface disappearing by March 9. But onchain approvals users had granted to Magic Eden's marketplace contracts through setApprovalForAll were never revoked. That permission remained active in users' wallets long after the website itself vanished, according to security researcher StarPlatinum, who wrote on X:

"If you previously gave a marketplace contract permission to transfer your NFTs using setApprovalForAll that permission can remain active in your wallet even after the website disappears."

On September 25, transactions began appearing as sales through Magic Eden's contracts priced at 0 ETH, with all 3,832 NFTs funneled into a single address beginning with 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33.

The white hat rescue and Yuga Labs' involvement

Sixteen minutes after the transfers began drawing attention, security researcher 0xQuit, who also serves as Yuga Labs' VP of Blockchain, publicly confirmed the wallet was under his control rather than an attacker's. Yuga Labs CEO Michael Figge said the issue was discovered hours earlier and that 0xQuit was handling the affected assets within the scope of a white-hat rescue operation. Quit said the NFTs are secured at that address and will be returned to their original owners once the underlying risk is resolved.

A separate, larger incident tied to the same underlying bug

A related but distinct incident surfaced the same day involving Magic Eden's Payment Processor V2. According to crypto commentator Jeremy, an attacker exploited a bug in that system, and 0xQuit again intervened, this time rescuing more than 23,000 NFTs worth approximately $5.7 million before the hacker could reach them. Jeremy noted that some assets were not saved in time:

"However some NFTs were still drained alongside 660 WETH worth $1.7M."

Payment Processor V2 refers to a specific smart contract system marketplaces use to handle NFT sales, royalty distribution, and payment settlement, distinct from the core marketplace listing contracts. A vulnerability in a payment processor can potentially be exploited across any transaction routed through it, regardless of whether the front-end marketplace interface remains active. That the exploit affected Payment Processor V2 six months after Magic Eden shut down its EVM front end confirms the underlying contracts, not the website, are what carried the ongoing risk. A defunct interface does not deactivate the smart contracts it once pointed to; those contracts continue operating on-chain indefinitely unless explicitly deprecated at the contract level, which appears not to have happened here.

The combined losses across both incidents point to a total exposure well beyond the initial $1.5 million figure, with Jeremy's report bringing the confirmed drained amount to at least $1.7 million in WETH alone, on top of whatever NFT value was not recovered.

What setApprovalForAll actually grants and why it's dangerous long-term

setApprovalForAll is an Ethereum smart contract function that gives a specified address blanket permission to transfer any NFT from a specific collection held in a user's wallet, without requiring approval for each individual token. Marketplaces use this function to let users list and sell NFTs without repeatedly signing new transactions.

The function's danger lies precisely in its permanence. Once granted, that approval remains valid indefinitely unless the user manually revokes it through a separate transaction. Most wallet interfaces do not proactively surface old approvals, and most users have no reason to think about permissions granted to a marketplace that no longer has a working website. This is not a new attack category; wallet-draining scripts have exploited stale NFT and token approvals for years, but this incident is notable because the vulnerable approvals point to a marketplace's own contracts rather than a third-party phishing site, meaning the exposure originated from legitimate historical use of Magic Eden itself rather than a scam interaction.

Jeremy's closing line captured the broader pattern:

"Another morning another attack... Web3 is not safe these days."

Magic Eden had not disclosed the root cause or the full scope of affected wallets at the time of these reports.

Ondo Launches BlackRock-Powered Tokenized Portfolios | HODL FM NEWS
Ondo Finance launched three onchain portfolio tokens built on BlackRock strategies, giving eligible non-US investors single-token access to diversified allocations.
hodl-post-image

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.