Magic Eden users lose NFTs and $1.8 million in wETH to legacy approvals exploit

A Bored Ape-style illustration of an ape with blue skin, brown shoulder-length hair, a grimace with red lipstick, bloodshot heavy-lidded eyes, a skull-print scarf, and a nurse's topAll my Desperate ApeWives gone :( (attribution)
Exploiters took advantage of a legacy approvals bug in an old payment processor called Limit Break, which the platform had stopped using in late 2024. The bug affected listings on Magic Eden's EVM marketplace, which the company had shut down earlier this year. The attackers were able to steal numerous NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women, and 235 Desperate Apewives. Attackers also subsequently stole 660 wETH (~$1.78 million).

A whitehat rescue spearheaded by blockchain researcher 0xQuit took control of 23,155 NFTs he estimated to be worth "north of $5.7M USD", which he said would be returned to their owners after they revoked the permissions that made the assets vulnerable to theft.

Meter token prices crash after unauthorized mint

An exploiter was able to mint unbacked wrapped MTR and MTRG tokens, notionally priced at more than $2.3 million. They sold some of the tokens on a decentralized exchange, crashing the MTRG price by more than 88%. The price of the project's MTR token — which is supposed to maintain a stable price based on the cost to produce 10 kWh of electricity — also plummeted by approximately the same percentage. Meter has attributed the exploit to a "block validation flaw".

Meter paused the blockchain and bridge, and has urged people not to trade the token. They have warned that "Transactions after block 100731417 may not be honored", suggesting they are considering a blockchain rollback.

Meter suffered another bridge attack in February 2022, which amounted to $4.3 million.

Payy Network bridge fully drained of $1.8 million

The Payy Network, a stablecoin infrastructure company, disclosed that a bridge contract had been fully drained of funds, netting attackers $1.8 million. They later stated that the theft was "NOT a compromised key, social engineering or exploit of our off-chain infrastructure," but has not disclosed what it was. They also announced that the stolen funds were "users' non-custodial deposits to Payy Network / Payy Wallet", which is somewhat of an oxymoron.

Payy Network has halted all activity following the attack.

Duelbits crypto casino goes offline after $7 million theft

The Duelbits crypto gambling site lost around $7 million to an apparent hot wallet compromise. The site went offline shortly after the attack, and the company has said the site will stay offline "until we have clarity". The Curaçao-based platform offers casino games and sportsbetting.

Bitget crypto exchange hacked for $388 million, pauses withdrawals

Attackers stole $387.5 million in crypto assets from Bitget, a cryptocurrency exchange originally founded in Singapore and headquartered out of the Seychelles. Centralized stablecoin issuers Circle and Tether (issuers of USDC and USDT) froze $318,000 in stolen assets, but the vast majority were swapped to decentralized cryptocurrencies and have not been frozen.

Bitget CEO Gracy Chen has said the company believes that a North Korean cybercrime group may be behind the theft. Bitget halted withdrawals shortly after the theft was noticed, citing the need to prevent attackers from stealing more assets. Bitget has said they have sufficient assets to cover the stolen funds.