BTC $83,293.91 -1.63%
ETH $2,677.15 -0.28%
BNB $761.64 -2.11%
XRP $1.48 -2.48%
SOL $117.72 -4.17%
TRX $0.3355 +0.61%
DOGE $0.0931 -4.26%
ADA $0.2439 -4.69%
BCH $306.77 -7.85%
LINK $15.14 +7.94%
HYPE $86.85 -5.04%
AAVE $146.08 -5.51%
SUI $1.13 -10.12%
XLM $0.2248 +3.75%
ZEC $1,464.20 -8.51%
AAPL $338.59 -0.47%
AMZN $246.40 -1.52%
GOOGL $342.63 -0.39%
MSFT $509.78 -1.52%
META $717.46 -4.30%
NVDA $229.21 +1.82%
TSLA $357.98 -4.14%
SNDK $1,712.63 -3.96%
INTC $115.93 -7.28%
SPCX $145.94 -2.27%
MU $1,053.88 -3.75%
AMD $609.57 -4.12%
BTC $83,293.91 -1.63%
ETH $2,677.15 -0.28%
BNB $761.64 -2.11%
XRP $1.48 -2.48%
SOL $117.72 -4.17%
TRX $0.3355 +0.61%
DOGE $0.0931 -4.26%
ADA $0.2439 -4.69%
BCH $306.77 -7.85%
LINK $15.14 +7.94%
HYPE $86.85 -5.04%
AAVE $146.08 -5.51%
SUI $1.13 -10.12%
XLM $0.2248 +3.75%
ZEC $1,464.20 -8.51%
AAPL $338.59 -0.47%
AMZN $246.40 -1.52%
GOOGL $342.63 -0.39%
MSFT $509.78 -1.52%
META $717.46 -4.30%
NVDA $229.21 +1.82%
TSLA $357.98 -4.14%
SNDK $1,712.63 -3.96%
INTC $115.93 -7.28%
SPCX $145.94 -2.27%
MU $1,053.88 -3.75%
AMD $609.57 -4.12%

authorization

All
Article
Flash

Magic Eden: Current open orders are not affected by this vulnerability; users in the EVM market from February to October 2024 need to revoke related contract authorizations

Magic Eden announced that the vulnerability occurred in the NFT trading protocol Payment Processor V2 maintained by Limit Break. Magic Eden adopted this protocol for EVM network transaction settlements in 2024 but stopped using V2 in October 2024 and will completely shut down the EVM market in the first quarter of 2026. Therefore, NFTs currently listed on Magic Eden are not affected by this vulnerability.NFTs listed through its EVM market between February and October 2024 may be affected, while listings after October 2024 are generally not impacted. The platform is contacting the protocol owner and maintainer Limit Break to explore other risk mitigation measures, including pausing protocol transfers, and will continue to investigate the actual scope of the impact.Magic Eden reminds users who have listed or traded NFTs on its EVM market to revoke relevant contract authorizations on the Ethereum, Polygon, and Base networks. Users can filter the address through revoke.cash and revoke all authorizations marked as "approved for all" for NFTs. Magic Eden emphasizes that revoking authorization cannot recover assets that have already been transferred.Yuga Labs' Vice President of Blockchain Quit stated today that at 9 AM Eastern Time, attackers exploited the Payment Processor V2 vulnerability to steal a large number of NFTs. After contacting the LimitBreak team, the latter quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain is also temporarily unable to be paused. Therefore, the team implemented a white-hat operation, successfully transferring and protecting 23,155 NFTs valued at over 5.7 million dollars.

Chengming Technology issued a letter holding ZCode accountable for uploading data without authorization

Taiyuan Chengming Technology Co., Ltd. sent a letter to Beijing Zhipu Huazhang Technology Co., Ltd., raising multiple demands regarding the alleged unauthorized upload of company data assets and trade secrets by its ZCode client, and reserving the right to pursue legal accountability. Chengming Technology pointed out that although Zhipu has publicly apologized for the "silent upload of user local repository data" and claimed to have fixed the issue, independent evidence collection revealed that the upload behavior was automatically triggered and occurred in bulk, including complete archived files such as project source code, system architecture, version control history, database passwords, cloud service credentials, and employee personal information, far exceeding the scope of collection stated in its Privacy Policy.Although the client was updated to version 3.12.3 on September 16, upload behavior was still detected in the early hours of the day Zhipu publicly apologized, raising doubts about the actual effectiveness of the "fix." At the same time, the ZCode client’s network requests pointed to a Singapore entity, while the service agreement was signed with Beijing Zhipu Huazhang, requesting clarification on the responsible party for this upload, as well as whether the data was transmitted abroad or stored overseas.Chengming Technology demanded that Zhipu respond in writing by October 10 and complete the immediate cessation of processing and thorough deletion of all uploaded data and related derivative data, caches, and backups, provide a complete list of processing situations, clarify the data's whereabouts, whether it was shared with third parties, whether it was used for model training, and whether cross-border transmission occurred, explain the management of encryption private keys and complete operation logs, clarify the exact scope of "destruction" mentioned in previous public responses, issue proof of deletion completion, provide a written commitment not to upload without authorization again, legally provide access, copying, and explanation of personal information, and designate formal communication channels, among other matters. Currently, Zhipu has not publicly responded to the aforementioned letter.

The American Securities Transfer Association wrote to the SEC: Third-party tokenized stocks pose risks and should prioritize the issuer authorization model

According to CoinDesk, as the competition for tokenization in the capital markets heats up, the Securities Transfer Association (STA) recently submitted a letter of opinion to the U.S. Securities and Exchange Commission (SEC), warning that stock tokens issued by third-party organizations may undermine market integrity and calling on regulators to prioritize support for tokenized securities authorized by publicly listed companies in future rule-making.The STA represents several Wall Street transfer agents, whose members believe that true tokenized stocks should be formally authorized by the issuing company and recorded in the official shareholder register, rather than created as "packaged" token products by independent platforms.The association pointed out that third-party stock tokens may confuse investors about the actual rights they hold and expose them to risks related to platform credit, custody, and operations, without establishing a direct legal relationship with the publicly listed company. Therefore, any innovative exemptions, pilot projects, or permanent regulatory frameworks for tokenized securities should prioritize the issuer-supported model.The STA also urged the SEC to reform the existing Direct Registration System (DRS), arguing that the current U.S. securities custody system is inadequate to meet the real-time transfer and settlement needs of on-chain securities, and suggested that regulators collaborate with the Depository Trust & Clearing Corporation (DTCC) to optimize the digital securities infrastructure.Currently, the global market for tokenized stocks, valued at approximately $2 billion, is primarily dominated by third-party models, including products launched by Ondo Finance and Kraken, while organizations like Securitize and Figure adopt the issuer authorization model.
app_icon
ChainCatcher Building the Web3 world with innovations.