Magic Eden Responds to Security Incident: Source Traced to Third-Party Protocol Flaw

On September 25th, Magic Eden CEO Jack issued an official statement addressing recent community concerns regarding a security incident. He emphasized that the Magic Eden platform itself was not attacked or compromised. The root cause was identified as a security vulnerability within the trading protocol and its associated smart contract provided by their partner, Limit Break.

Root Cause and Platform Response

Disclosures revealed that the implicated smart contract protocol was once integrated by Magic Eden during an earlier phase of its operations. Jack clarified that the platform had completely discontinued use of this protocol two years ago, indicating that its core systems were not directly exposed to this specific risk.

The Magic Eden team is now in urgent discussions with Limit Break to formulate next steps. Key action points include:

  • Advocating for a protocol-level pause on all asset transfers related to the exploited vulnerability.
  • Strongly advising all users to immediately review and revoke any asset approvals granted to this protocol via Magic Eden.
  • Continuing to assess the impact and pledging to share detailed updates with the community as the situation evolves.

White-Hat Hacker Aids in Mitigation

A white-hat hacker known as 0xQuit played a crucial role in the incident response. Jack extended specific thanks, noting that 0xQuit's timely intervention helped recover some at-risk assets, effectively containing the potential scale of losses. This action provided valuable time for the official response.

This event underscores the critical importance of thorough security audits and ongoing risk monitoring for third-party components within the Web3 ecosystem. Even with a robust core platform, integrated external protocols can introduce vulnerabilities. Magic Eden's swift clarification and response aim to maintain user trust and prompt broader industry attention to supply-chain security.