Magic Eden users lose NFTs and $1.8 million in wETH to legacy approvals exploit

A Bored Ape-style illustration of an ape with blue skin, brown shoulder-length hair, a grimace with red lipstick, bloodshot heavy-lidded eyes, a skull-print scarf, and a nurse's topAll my Desperate ApeWives gone :( (attribution)
Exploiters took advantage of a legacy approvals bug in an old payment processor called Limit Break, which the platform had stopped using in late 2024. The bug affected listings on Magic Eden's EVM marketplace, which the company had shut down earlier this year. The attackers were able to steal numerous NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women, and 235 Desperate Apewives. Attackers also subsequently stole 660 wETH (~$1.78 million).

A whitehat rescue spearheaded by blockchain researcher 0xQuit took control of 23,155 NFTs he estimated to be worth "north of $5.7M USD", which he said would be returned to their owners after they revoked the permissions that made the assets vulnerable to theft.

Meter token prices crash after unauthorized mint

An exploiter was able to mint unbacked wrapped MTR and MTRG tokens, notionally priced at more than $2.3 million. They sold some of the tokens on a decentralized exchange, crashing the MTRG price by more than 88%. The price of the project's MTR token — which is supposed to maintain a stable price based on the cost to produce 10 kWh of electricity — also plummeted by approximately the same percentage. Meter has attributed the exploit to a "block validation flaw".

Meter paused the blockchain and bridge, and has urged people not to trade the token. They have warned that "Transactions after block 100731417 may not be honored", suggesting they are considering a blockchain rollback.

Meter suffered another bridge attack in February 2022, which amounted to $4.3 million.