Magic Eden Approval Bug Nearly Cost $5.7M in NFTs
A leftover permission setting on Magic Eden almost let an attacker walk away with $5.7 million (USD) in NFTs. Whitehat hackers moved first, but the same forgotten setting could be sitting in your wallet right now.
What actually happened
According to The Block, old approval permissions on Magic Eden left $5.7 million (USD) worth of NFTs open to exploitation. Whitehat security researchers spotted the exposure and moved 23,155 tokens to safety before anyone could drain them. The report does not name the collections affected, give a discovery date, or confirm a public statement from Magic Eden. No user funds were reported lost. The rescue happened before any malicious transaction went through, per the same report. Details on how the legacy approvals were built have not been released.
How we got here
Approval risk is not new to NFT marketplaces. Granting a platform permission to move your NFT stays active long after a listing expires, unless you manually cancel it. When marketplaces update their contracts, old permissions can be left behind and forgotten. Attackers who spot these dormant approvals can sometimes move tokens without asking the owner again. This has happened on other platforms before. Magic Eden's case fits that same pattern, just at a larger scale, $5.7 million (USD) in exposed value sitting in permissions nobody thought to check.
Why this matters for you
If you have ever listed an NFT on Magic Eden, or any marketplace, go check your approvals now and revoke anything you no longer use. For everyday wallet users, including those managing assets through bonuz, this is a nudge to treat approval cleanup as routine, not optional. For builders, it is a reminder that legacy permissions carry real cost long after a contract upgrade ships. Marketplaces may start auditing old approvals themselves instead of waiting for a whitehat to find the gap first.
The bigger question
How many dormant approvals, across how many marketplaces, are sitting unexamined right now? Should platforms be required to expire permissions automatically, instead of leaving that job to users who may never think to check again?
What to watch
Magic Eden has not published an official timeline or statement as of this report. Watch for any disclosure naming the affected collections or explaining how the legacy approvals came about. Expect wider talk across NFT platforms about building approval expiration into marketplace design by default.






