A $5.7M NFT “disappeared” — wait, a white-hat raced ahead of the hackers and salvaged it. The real theft, however, was recorded under another account.
It all starts with a contract permission that had been left unattended for two years. Payment Processor V2. Magic Eden disabled it back in October last year, and this year’s first quarter even shut down the entire EVM market. The official statement was crystal clear: “No live order listings were affected.”
The issue is that even if the system is shut down completely, the “Agree” button you clicked two years ago still keeps the permissions alive. Someone dug up this old key — the white-hats worked through the night to rescue 23,155 NFTs worth $5.7M and stop the hackers. But 660 WETH weren’t rescued in time. Combined with other losses, Revoke.cash estimates that at least $2.8M was actually stolen, including 580 WETH.
The first version that spread was “Magic Eden was hacked,” scaring people into sharing screenshots everywhere. But as it kept circulating, the direction shifted — technical accounts like 0xQuit explained clearly how the V2/V3 vulnerability mechanisms work, and Revoke.cash directly posted links showing how to revoke authorizations. With 74,093 views and 147 shares, it wasn’t pushing panic — it was pushing a responsible task: go check what old permissions you still have in your wallet that haven’t been touched in three years.
The truly valuable lesson is this: shutting down a product doesn’t mean risk is zero. Old authorizations are still live time bombs. V3 is still running — this time, official intervention by hand prevented a bigger disaster.
On this $ME move, I’m leaning toward volatility rather than bearishness — the problem is an old backdoor left in the contract from two years ago, unrelated to today’s platform business. There’s no reason to use that to justify a sell-off. What you should actually watch isn’t the ME price, but the V3 system that’s still running: this time, manual intervention caught it — if it isn’t caught next time, that’s the real signal to panic.
$ME #NFT #Web3Security #MagicEden
It all starts with a contract permission that had been left unattended for two years. Payment Processor V2. Magic Eden disabled it back in October last year, and this year’s first quarter even shut down the entire EVM market. The official statement was crystal clear: “No live order listings were affected.”
The issue is that even if the system is shut down completely, the “Agree” button you clicked two years ago still keeps the permissions alive. Someone dug up this old key — the white-hats worked through the night to rescue 23,155 NFTs worth $5.7M and stop the hackers. But 660 WETH weren’t rescued in time. Combined with other losses, Revoke.cash estimates that at least $2.8M was actually stolen, including 580 WETH.
The first version that spread was “Magic Eden was hacked,” scaring people into sharing screenshots everywhere. But as it kept circulating, the direction shifted — technical accounts like 0xQuit explained clearly how the V2/V3 vulnerability mechanisms work, and Revoke.cash directly posted links showing how to revoke authorizations. With 74,093 views and 147 shares, it wasn’t pushing panic — it was pushing a responsible task: go check what old permissions you still have in your wallet that haven’t been touched in three years.
The truly valuable lesson is this: shutting down a product doesn’t mean risk is zero. Old authorizations are still live time bombs. V3 is still running — this time, official intervention by hand prevented a bigger disaster.
On this $ME move, I’m leaning toward volatility rather than bearishness — the problem is an old backdoor left in the contract from two years ago, unrelated to today’s platform business. There’s no reason to use that to justify a sell-off. What you should actually watch isn’t the ME price, but the V3 system that’s still running: this time, manual intervention caught it — if it isn’t caught next time, that’s the real signal to panic.
$ME #NFT #Web3Security #MagicEden