According to Quit monitoring, the Payment Processor V2 (PPV2) vulnerability attack is still ongoing. Even if users were not affected by the incident, as long as the relevant authorizations have not been revoked, assets may still be at risk, and it is recommended to revoke the authorizations immediately. About an hour ago, a certain address lost 0.15246 WETH in the next block after accepting an offer and receiving funds. The attacker paid 99% of this amount as a tip to Titan Builder, keeping only about 0.0015 ETH, making it nearly impossible to recover the funds through front-running. Quit suggests that OpenSea should check whether there are still risk authorizations before users accept offers and request users to revoke them beforehand; when transferring NFTs, it is also advised to check if the receiving address still has relevant authorizations.
All Comments