0x07b2614307b2…07b26140

ConfirmedSecurity602 vB149 sat/vB3 min decode

Magic Eden Warns 23,155 NFTs Rescued From Payment Processor Exploit

A whitehat operation saved 23,155 NFTs worth over $5.7 million from a Limit Break Payment Processor V2 exploit that hit old Magic Eden EVM listings.

Outputs

  1. 23,155 NFTs worth more than $5.7 million were rescued in a whitehat operation after a Payment Processor V2 exploit.

  2. 660 WETH exposed to a reverse version of the exploit could not be recovered.

  3. Magic Eden's EVM marketplace listings from roughly February to October 2024 are affected.

  4. Users must revoke approvals on Ethereum, Polygon and Base via Revoke.cash.

  5. On September 25 an attacker stole 10 Meebits, 50 Otherdeeds, 10 WoW and 235 Desperate ApeWives NFTs.

A whitehat operation rescued 23,155 NFTs worth more than $5.7 million after an attacker exploited a bug in Limit Break's Payment Processor V2, the protocol Magic Eden used to settle trades on its now-closed EVM marketplace, the marketplace warned Friday.

Magic Eden said NFTs listed on its EVM marketplace between roughly February and October 2024 could be exposed. The company adopted the Limit Break-built contract to settle trades in 2024, stopped using it that October, and shut its EVM marketplace entirely in early 2026.

"No live Magic Eden listings were impacted in this exploit," Magic Eden said in a post on X.

What exactly went wrong?

The vulnerability sits in lingering approvals. When users list an NFT, they typically grant the underlying contract permission to move that token, and that permission remains active until explicitly revoked. Because Magic Eden's marketplace is gone, the approvals it required still linger on-chain, attached to Payment Processor V2.

At 9AM EST on September 25, an attacker abused the bug to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives, according to 0xQuit, vice president of blockchain at Yuga Labs.

"It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject," 0xQuit wrote on X.

Limit Break paused Payment Processor V3, which contained the same flaw. V2 could not be paused. That structural limitation forced a whitehat rescue — an operation in which friendly hackers move vulnerable assets to safety before malicious actors can reach them.

"All in all, we rescued 23,155 NFTs worth north of $5.7M USD," 0xQuit wrote. Owners will be able to reclaim their assets after revoking the contract approvals, he added.

Not everything was saved. Roughly 660 WETH exposed to a reverse version of the exploit could not be recovered in time.

What should affected users do now?

Magic Eden urged anyone who listed or traded on its EVM marketplace to revoke the V2 contract's "approved for all" permissions on three networks:

  • Ethereum
  • Polygon
  • Base

The marketplace directed users to Revoke.cash for the operation. One caveat matters: revoking prevents future theft but does not return tokens that have already moved. Users who lost assets in the initial September 25 attack will need to pursue recovery separately from any revocation.

Why does a closed marketplace still carry risk?

The episode illustrates an operational reality of NFT market structure: marketplace shutdowns do not unwind the on-chain permissions users granted while trading. Magic Eden dropped Ethereum and Bitcoin support in February to focus on Solana and its crypto casino, Dicey, and later wound down its multichain wallet. Yet approvals granted to Payment Processor V2 persisted across three chains long after the marketplace stopped settling trades.

The incident also lands at a rough moment for crypto users. Just a day before Magic Eden's warning, unknown hackers swiped more than $380 million in Ethereum and other assets from the Bitget exchange — the largest crypto hack of the year so far.

What happens next?

The immediate deadline is behavioral, not regulatory: every day a stale "approved for all" permission remains active on Ethereum, Polygon or Base, the holder's assets stay exposed to the same exploit. Owners of the 23,155 rescued NFTs must revoke approvals before reclaiming, meaning the recovery process itself depends on users acting promptly.

Limit Break has already paused V3, but V2 remains live and unpausable by design, leaving revocation the only durable mitigation until the affected approvals age out of use.

via t.co (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles