Magic Eden / Limit Break Hack
あなたのアドレスが影響を受けていないかご確認ください。
On 25 September 2026, security researcher 0xQuit used a vulnerability in Limit Break's Payment Processor, the NFT marketplace protocol behind Magic Eden's former Ethereum marketplace, to move 3,832 NFTs, reportedly worth around $1.4M, out of wallets that had approved Payment Processor V2 as an operator. The transfers were executed through the contract as 0 ETH sales, and 0xQuit stated that this was a whitehat rescue and that the NFTs are held in a custody wallet and will be returned once they are no longer at risk. Users have been urged to revoke approvals to Payment Processor V2 on Ethereum and Payment Processor V3 on ApeChain, as cancelling listings or bumping the master nonce does not protect against the issue. Details of the vulnerability have not been published yet, and it is not yet clear whether any NFTs were taken by malicious actors. This entry will be updated as more information becomes known.
影響を受けたユーザーは、承認を取り消さない限りリスクにさらされ続けるため、以下の Revoke.cash エクスプロイトチェッカーを使用して、ご自身が安全であることを確認することをお勧めします。
次回は自動的に取り消しましょう
Revoke Ultimateは承認を24時間体制で監視し、今回のようなエクスプロイトが確認された場合には、あなたが眠っている間でも自動的に承認を取り消します。
自動取り消しの仕組みを見る →