BTC $84,309.07 +0.41%
ETH $2,691.87 +0.11%
BNB $770.80 -0.42%
XRP $1.51 -3.24%
SOL $120.15 -0.44%
TRX $0.3330 -1.33%
DOGE $0.0955 -2.53%
ADA $0.2506 -2.29%
BCH $330.96 -1.79%
LINK $14.04 -0.75%
HYPE $92.92 +0.92%
AAVE $154.76 +0.16%
SUI $1.14 -0.55%
XLM $0.2132 -2.51%
ZEC $1,634.11 +6.30%
AAPL $340.36 -0.19%
AMZN $249.67 +0.00%
GOOGL $343.21 -0.01%
MSFT $517.78 +0.15%
META $748.00 +0.36%
NVDA $224.47 -0.06%
TSLA $372.24 +0.08%
SNDK $1,769.57 -0.29%
INTC $123.74 +0.48%
SPCX $148.57 0.00%
MU $1,088.97 +0.61%
AMD $628.79 -0.38%
BTC $84,309.07 +0.41%
ETH $2,691.87 +0.11%
BNB $770.80 -0.42%
XRP $1.51 -3.24%
SOL $120.15 -0.44%
TRX $0.3330 -1.33%
DOGE $0.0955 -2.53%
ADA $0.2506 -2.29%
BCH $330.96 -1.79%
LINK $14.04 -0.75%
HYPE $92.92 +0.92%
AAVE $154.76 +0.16%
SUI $1.14 -0.55%
XLM $0.2132 -2.51%
ZEC $1,634.11 +6.30%
AAPL $340.36 -0.19%
AMZN $249.67 +0.00%
GOOGL $343.21 -0.01%
MSFT $517.78 +0.15%
META $748.00 +0.36%
NVDA $224.47 -0.06%
TSLA $372.24 +0.08%
SNDK $1,769.57 -0.29%
INTC $123.74 +0.48%
SPCX $148.57 0.00%
MU $1,088.97 +0.61%
AMD $628.79 -0.38%

vulnerability

All
Article
Flash

Magic Eden: Current open orders are not affected by this vulnerability; users in the EVM market from February to October 2024 need to revoke related contract authorizations

Magic Eden announced that the vulnerability occurred in the NFT trading protocol Payment Processor V2 maintained by Limit Break. Magic Eden adopted this protocol for EVM network transaction settlements in 2024 but stopped using V2 in October 2024 and will completely shut down the EVM market in the first quarter of 2026. Therefore, NFTs currently listed on Magic Eden are not affected by this vulnerability.NFTs listed through its EVM market between February and October 2024 may be affected, while listings after October 2024 are generally not impacted. The platform is contacting the protocol owner and maintainer Limit Break to explore other risk mitigation measures, including pausing protocol transfers, and will continue to investigate the actual scope of the impact.Magic Eden reminds users who have listed or traded NFTs on its EVM market to revoke relevant contract authorizations on the Ethereum, Polygon, and Base networks. Users can filter the address through revoke.cash and revoke all authorizations marked as "approved for all" for NFTs. Magic Eden emphasizes that revoking authorization cannot recover assets that have already been transferred.Yuga Labs' Vice President of Blockchain Quit stated today that at 9 AM Eastern Time, attackers exploited the Payment Processor V2 vulnerability to steal a large number of NFTs. After contacting the LimitBreak team, the latter quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain is also temporarily unable to be paused. Therefore, the team implemented a white-hat operation, successfully transferring and protecting 23,155 NFTs valued at over 5.7 million dollars.

Liquid Network releases emergency fix: Elements v23.3.4 fixes Proof verification cache vulnerability

Liquid Network has released the latest update stating that the emergency version Elements v23.3.4 is now online. Functionary nodes have immediately begun upgrading and all Liquid node operators are advised to synchronize updates. This version addresses the previously discovered Proof verification cache vulnerability and strengthens the cache keys used for Range Proof.Regarding network recovery, Blockstream states that it is still formulating a recovery plan, which is expected to proceed in three phases: restoring block production while continuing to suspend Peg operations; replaying verified valid transactions; and restoring Peg operations after the network status is fully restored and funds are confirmed to be returned. Currently, the first two phases are being tested in parallel, and any phase will only advance once safety is confirmed. Liquid Network indicates that Elements v23.3.4 has completed multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams.At the same time, Liquid Network reminds users to be vigilant against fraudulent upgrade websites exploiting this incident. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or recovery phrases.
app_icon
ChainCatcher Building the Web3 world with innovations.