0x70f8962f70f8…70f8962c
Magic Eden Warns Old Ethereum Listings Hit by Payment Processor Exploit
Magic Eden disclosed that NFTs on its now-closed EVM marketplace from February-October 2024 remain exposed to a flaw in Limit Break's Payment Processor V2, prompting a whitehat rescue of 23,155 NFTs worth over $5.7 million.

Outputs
23,155 NFTs valued at more than $5.7 million were rescued in a whitehat operation on September 25, 2026
660 WETH exposed to a reverse variant of the exploit was not recovered
Affected listings were created on Magic Eden's EVM marketplace between February and October 2024
Attacker initially stole 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives at 9 a.m. EST
Limit Break paused V3 but could not pause V2 due to the contract's immutability
Magic Eden disclosed on Friday that NFTs listed on its now-closed EVM marketplace between roughly February and October 2024 remain exposed to an exploit targeting Limit Break's Payment Processor V2, prompting a whitehat rescue of 23,155 NFTs valued at more than $5.7 million.
The flaw, dormant for nearly two years, resurfaced on September 25 when an attacker drained user wallets at 9 a.m. EST, according to Yuga Labs Vice President of Blockchain 0xQuit. "No live Magic Eden listings were impacted in this exploit," Magic Eden said on X. The attack predated the company's February exit from Ethereum and Bitcoin support.
What happened on September 25?
0xQuit reported the initial theft within hours. The attacker took 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. A full inventory of stolen items was not disclosed.
The exploit hinged on lingering token approvals. When users listed or traded NFTs on Magic Eden's EVM marketplace, they granted the V2 contract blanket permission to move assets. Those allowances persisted after listings closed, leaving wallets vulnerable.
"All in all, we rescued 23,155 NFTs worth north of $5.7M USD," 0xQuit wrote. "It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the [same risk]."
Why couldn't Limit Break pause V2?
Limit Break attempted to freeze V3, which carried the same flaw. V3 was paused successfully. V2, however, could not be paused, forcing a whitehat rescue operation in which friendly actors preemptively moved vulnerable assets to safety.
The whitehat team recovered 23,155 NFTs but failed to retrieve 660 wrapped Ethereum (WETH) exposed to a reverse variant of the exploit. Owners of salvaged NFTs can reclaim them after revoking the relevant approvals, according to 0xQuit.
Which chains are affected?
Magic Eden urged any past user to revoke the V2 contract's "approved for all" permissions on three networks:
- Ethereum mainnet
- Polygon
- Base
Revocation must be executed through Revoke.cash. Magic Eden warned that revoking approvals will not reverse any tokens already moved by the attacker.
How did Magic Eden end up running V2?
Magic Eden integrated the Limit Break protocol in 2024 to settle EVM trades. Usage ended that October. The marketplace shut its EVM operations in early 2026 and dropped Bitcoin support the same month, refocusing on Solana and its crypto casino product, Dicey.
The company later wound down its multichain self-custodial wallet, telling users holding Solana assets to migrate elsewhere.
How serious is the exposure?
The episode lands during a difficult week for crypto security. On September 24, unknown hackers siphoned more than $380 million in Ethereum and other assets from Bitget exchange wallets, making it the largest crypto hack of 2026 to date. The Magic Eden incident adds a second contrast case. Approvals left unchecked on legacy contracts remain a structural risk across EVM markets, not a single-protocol anomaly.
0xQuit warned that the V2 contract's immutability leaves only one path forward for users: manual revocation. Magic Eden reiterated the same point, emphasizing that the marketplace's current Solana operations remain unaffected.
Users holding listings from the February-to-October 2024 window should verify wallet approvals within 24 hours to prevent further drainage, given the V2 contract cannot be paused.
via cdn.decrypt.co (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles