On September 30, Quit, Vice President of Blockchain at Yuga Labs, issued a reminder that the Payment Processor V2 (PPV2) vulnerability attacks are still ongoing. Even if users were not affected by the incident on September 25, their assets may still be at risk as long as the relevant authorizations have not been revoked. Quit urged users to revoke their authorizations immediately. He noted that about an hour ago, the address 0x3B13...3327 lost 0.15246 WETH in the next block after accepting an offer and receiving funds. The attacker paid 99% of this amount as a tip to Titan Builder, retaining only about 0.0015 ETH, making it nearly impossible to recover the funds through front-running. Quit suggested that OpenSea consider checking for risk authorizations before users accept offers and require revocation beforehand; when transferring NFTs, users should also verify that the receiving address does not have relevant authorizations.
All Comments