xiyu
xiyu|Sep 25, 2026 13:53
The user initially granted 'approve for all' permissions through Magic Eden's EVM marketplace. As an integrator, the platform has the responsibility to inform and manage the long-term validity of old approvals. Some in the community have directly criticized this as a blame game. As a 'temporary update,' the information is clearly incomplete. The announcement does not disclose the number of affected wallets, the scale of the losses, the specific exploitation method of the vulnerability, or why the old approvals could still be exploited nearly two years after the marketplace was shut down. Users had to learn from other sources that approximately $2.8 million was stolen, and white hats managed to rescue NFTs worth about $5.7 million. This kind of 'deflect first, investigate later' approach shows the platform is delaying a substantive response. There’s almost no reflection on the systemic risk of 'unlimited approvals.' Listings authorized between February and October 2024 will still be valid until 2026, which indicates that when the platform shut down the EVM marketplace, it neither proactively reminded users to revoke old approvals nor adequately warned about the permanent risks of 'approve for all' when integrating the Limit Break protocol. For users who still have active approvals from that time, the most practical action is to immediately visit http://revoke.cash to revoke NFT and token approvals for Ethereum, Polygon, and Base.
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads