# malicious approval — X 热门讨论 (2026-09-25 11:16 UTC)

## @0xD0M_ (Dominic) · 09-25 10:09 · ♥31 ↻8 💬11 I’m scared friends.

I See people clown Bitget over the $351M incident like it’s just a “skill issue” or bitget came after Hyperliquid then and we should come after them now helooo are we missing the bigger picture here?.

The crazy part is that the attacker apparently didn’t need to steal Bitget’s private keys.

Bitget uses a tiered wallet system, with cold wallets separated from the hot and warm wallets used for operational liquidity. @bitget says the affected funds came from a limited number of hot wallets while its cold wallets remained untouched.

So how can hundreds of millions move without someone simply stealing a private key?

Because an exchange is not just a private key.

It’s an entire infrastructure stack:

>Hot and warm wallets.

>Withdrawal systems.

>Transaction construction.

>Approval policies.

>Multisigs.

>Backend services.

>Cloud infrastructure.

>Internal APIs.

>Signing infrastructure.

>Third-party security systems.

If one critical layer is compromised, an attacker may be able to make legitimate infrastructure perform an illegitimate action.

Think about it like this:

You don’t necessarily steal the bank vault key.

You compromise the system telling the bank which doors should open.

That’s why this isn’t just a Bitget problem per se, any malicious group with just the right use of ai can come after your stack which I just mentioned.

The same question applies to every CEX, custodian, bridge, stablecoin issuer, DeFi protocol, treasury and infrastructure provider:

What happens if one trusted component is compromised?

We have spent years in Crypto teaching people to protect private keys.

But the attack surface is much bigger than the key itself.

And this is where clowning another protocol or exchange because it got hacked becomes dangerous.

Today it’s Bitget.

Tomorrow it could be the exchange you use, the bridge you trust, the stablecoin you hold, the multisig securing a treasury or the infrastructure underneath a protocol you use every day.

Security failures don’t care about favorites

The biggest mistake you can make after watching $351M hack is thinking:

“Glad that’s their problem.”

It could be yours next.

Bitget’s investigation into the exact attack vector is still ongoing, so the technical root cause shouldn’t be treated as confirmed yet.

But the lesson is already clear:

Crypto custody isn’t just about protecting the keys.

It’s about protecting every system that can convince a legitimate wallet to move money. Be it a hot wallet or a cold wallet > 引用 @GracyBitget: 最新的进展同步一下:我们正在与独立第三方专家 @Mandiant 和 @SlowMist_Team 合作,对此次事件进行全面调查。 其他几点都是说过的,我再强调一下: -我们的首要任务是保障用户。用户余额保持完整,Bitget 用户保护基金将覆盖此次平台层面事件造成的影响。 -Bitget Wallet 为自托管钱包,运行于与 Bitget Exchange 完全分离且独立的基础设施之上,未受此次事件影响。 -Bitget Exchange 平台的充值交易奖励等功能都继续正常运行。在我们完成额外安全核查期间,提币功能暂时暂停;待我们确认可以安全恢复后,将尽快恢复提币。 -我们明白在此类事件发生时,用户希望尽快获得答复。我们将通过Bitget官方渠道及时发布最新进展。请关注我的和@bitget @xiejiayinBitget 的 X账号以及Bitget官方公告。 https://x.com/0xD0M_/status/2103426782993010942

## @0xfortizo (Fortizo) · 09-25 10:32 · ♥31 ↻6 💬9 Magic Eden closed its EVM NFT marketplace in March.

Today, NFTs are still being pulled out of wallets through the contract behind it, for 0 ETH, via approvals people forgot about.

That's the thing about crypto approvals: they outlive the apps you gave them to.

Here's what approvals are, why you should revoke them regularly, and real examples across DeFi, NFTs and trading bots 👇

🔑 WHAT IS AN APPROVAL?

Before a dApp can move your tokens to swap, bridge, stake, lend or list them, you grant a permission that lets its smart contract move them for you.

That's an approval. Once it's granted, the contract can move those assets whenever it wants, up to the limit you set, without asking you again.

The main types:

• approve(): lets a contract spend one token. Many dApps ask for "unlimited" so they never have to ask twice. • setApprovalForAll(): the NFT version. It gives an operator access to EVERY NFT you hold in that collection, including ones you buy later. • Permit / Permit2: approvals granted with a gasless signature. No transaction and no fee, so it feels harmless. It isn't. • Marketplace listing signatures: off-chain orders that use the NFT approvals you've already given. • EIP-7702 batching (since 2025): one confirmation can bundle several approvals and transfers at once.

⚠️ WHY THEY'RE DANGEROUS

1. Most approvals never expire. One you gave in 2021 is still live today. 2. Disconnecting your wallet from a site does NOT revoke anything. Approvals live on-chain. 3. You're trusting that contract, and whoever controls it, indefinitely. Code gets upgraded, new modules get added, bugs turn up years later, teams walk away, admin keys get stolen, DAOs get taken over. 4. Nobody needs your seed phrase. They only need one weak spot in any contract you ever approved.

🏦 DEFI

• @SushiSwap (Apr 2023): a new router had been live for 4 days when a bug let attackers pull tokens from anyone who'd approved it. ~$3.3M gone, including 1,800 ETH from one user (0xSifu).

• @lifiprotocol (Jul 2024): a newly added contract module had a bug. $10M+ was drained from 153 wallets, all of which had given INFINITE approvals. Exact-amount approvals were safe.

• @BungeeExchange ( @SOCKETProtocol ) (Jan 2024): a new route with an input-validation bug. ~$3.3M taken from 200+ wallets with infinite approvals.

• SwapNet (Jan 2026): an arbitrary-call bug drained $13M+. The victims were users who had switched off Matcha's one-time approvals and left standing allowances instead.

• BarnBridge (Jul 2026) is the scariest one. The protocol had been dormant since 2023. An attacker spent ~0.34 ETH on governance tokens, which was enough for ~43% of the vote in a DAO nobody was watching. They passed a proposal, took control, and pulled ~$776K USDC from ~50 wallets with approvals from YEARS ago.

Those people didn't click anything bad. They just never revoked.

🖼️ NFTS

• Magic Eden / Limit Break (live today): attackers are using old approvals to Limit Break's Payment Processor to take NFTs for 0 ETH. Blockaid reported ~$1.7M stolen, and a whitehat moved 3,800+ NFTs out of exposed wallets. If you ever traded there on ETH or ApeChain, revoke those approvals now. more here ➙ https://t.co/uKRnFqb6Ye

• NFT Trader (Dec 2023): a bug in two OLD contracts let an attacker take NFTs from anyone who still had approvals on them. 36 BAYC and 18 MAYC came back only after the attacker was paid 120 ETH.

• Gondi (Mar 2026): a newly deployed NFT-lending contract let an attacker reuse existing approvals to take 78 NFTs (~$230K) including Art Blocks, Doodles and SuperRare. None of them were in a loan.

• Premint (Jul 2022): a hacked site showed a "verify your wallet" pop-up that was really setApprovalForAll. 300+ NFTs, ~$400K gone.

• Kevin Rose (Jan 2023): he signed ONE gasless message. His NFTs were already approved to OpenSea, so that signature let the scammer take 40 NFTs (~$1.1M), including 25 Chromie Squiggles.

🤖 TRADING BOTS & AGGREGATORS

• Maestro (Oct 2023): a router bug let an attacker take ~280 ETH of users' approved tokens. • Unibot (a week later): a new router with the same kind of bug. ~$640K.

Every bot, router and aggregator you've approved is a door you left open.

🌐 HIJACKED FRONT-ENDS: RIGHT URL, MALICIOUS PROMPT

• BadgerDAO (Dec 2021): a script injected into the real site added unlimited approvals for the attacker into users' normal clicks. Then the attacker cashed them in for ~$120M. The audited contracts were never touched. • CoW Swap (Apr 2026): attackers hijacked the real domain for ~4.5 hours and served an exact copy of the site. ~$1.2M was drained, including 219 ETH from one wallet.

🎣 SIGNATURE PHISHING

• Scam Sniffer: wallet drainers took $494M in 2024. That fell to ~$84M in 2025, but Permit/Permit2 signatures still made up ~38% of the $1M+ losses. The biggest single theft of 2025 was $6.5M from ONE Permit signature. • EIP-7702 batching: one batch confirmation on a fake Uniswap site hid transfers that cost a user $1.54M (Aug 2025).

🧹 HOW TO PROTECT YOURSELF

1. Check your approvals on https://t.co/wb5yTTHiQO, Rabby's Approvals tab, or Etherscan's Token Approval Checker. Type the URL yourself, because fake "revoke" sites are a favorite drainer trick. 2. Revoke anything unlimited you aren't actively using, anything tied to dead or deprecated protocols, and marketplace approvals for NFTs you aren't selling. Cancelling a listing does NOT remove the approval. 3. Approve exact amounts. MetaMask and Rabby let you edit the spend cap. Remember https://t.co/5sohnHdzkM: only the infinite approvals got hit. 4. Split your wallets: a vault that never connects to anything, and a hot wallet for mints, bridges, bots and new protocols. 5. Read before you sign. If you see setApprovalForAll, Permit, PermitBatch, a 0 ETH listing, or an "upgrade your account" prompt you didn't expect, stop. 6. Signed something sketchy? Revoke AND move your assets to a fresh wallet. Signed permits and listings can sit off-chain, where approval checkers can't see them, until someone uses them. 7. Make it a habit: check monthly, and after every mint, bridge, airdrop claim or new protocol you try.

Revoking costs a little gas, often pennies on L2s. Getting drained costs everything.

Your wallet is only as safe as the worst contract you ever approved.

Go check yours. 🔒 > 引用 @0xQuit: At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives.

It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the same exploit.

I got in touch with the team over at LimitBreak and they quickly paused Payment Processor V3, which was subject to the same exploit. Unfortunately, V2 was not pausable, so the only path towards protecting affected assets was to run a whitehat operation.

Similarly, V3 on ApeChain is temporarily in a state where it cannot be paused, so ApeChain assets approved to V3 needed to be saved as well.

All in all, we rescued 23,155 NFTs worth north of $5.7M USD.

We later discovered that a similar exploit could be used in reverse to steal WETH. 660 WETH was at risk, which we unfortunately were not fast enough to recover. Apologies to those affected.

Shout out to @Boomskite for flagging the initial exploit tx to me, and @coffeedev @0xjustadev and @whiteoakkong for acting quickly and assisting with the recovery.

All NFTs are safely relocated. Soon, owners will be able claim them back after revoking the exploitable approvals.

Addresses to revoke below. https://x.com/0xfortizo/status/2103432503650353298