1 min read

PPV2 Exploit Remains Active as Users Urged to Revoke Approvals

A wallet lost 0.15246 WETH after accepting an offer, with nearly all of the funds paid as a tip to Titan Builder.

Mentioned assets
Hands secure a cryptocurrency wallet beside a hardware device / TokenPost.ai
Hands secure a cryptocurrency wallet beside a hardware device / TokenPost.ai

The Payment Processor V2 (PPV2) exploit remains active, and users who have not revoked affected token approvals may still face asset risk, including those unaffected by the Sept. 25 incident.

Yuga Labs blockchain vice president Quit warned users to revoke the approvals immediately. The warning followed a loss involving wallet address 0x3B13...3327, which lost 0.15246 WETH in the block after accepting an offer and receiving funds.

The attacker paid 99% of the stolen WETH as a tip to Titan Builder and kept about 0.0015 ETH. That distribution left little opportunity to recover the funds through a front-running transaction.

Quit also urged OpenSea to check for active risky approvals before users accept offers and to review approvals associated with addresses receiving transferred NFTs. Users should revoke any affected PPV2 approvals immediately.

Loading…