Old Magic Eden Approvals Exposed 23,000 NFTs Before Whitehat Rescue
• September 25, 2026 3:13 pm • CommentsMagic Eden stopped using one of its old Ethereum payment contracts nearly two years ago. The approvals granted to that contract did not stop with it.
That gap left more than 23,000 NFTs exposed when an attacker found a flaw in Limit Break’s Payment Processor V2 this week. A whitehat rescue prevented a much larger loss, but the episode is a sharp warning for anyone who assumes an old marketplace approval disappears when the marketplace moves on.
Decrypt reported that Magic Eden used Payment Processor V2 to settle EVM trades in 2024, stopped using it that October and shut its EVM marketplace in early 2026. Users who listed NFTs between roughly February and October 2024 could still have “approve for all” permissions attached to the contract.
The exploit began with 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives taken through the flaw. Limit Break could pause its newer V3 contract, which had a similar weakness, but V2 could not be paused.
That forced defenders to move the exposed assets before the attacker could. Yuga Labs Vice President of Blockchain 0xQuit said the operation rescued 23,155 NFTs worth more than $5.7 million, with owners able to reclaim them after revoking the dangerous approvals.
The rescue was not complete. Another version of the exploit put 660 wrapped Ethereum at risk, and the whitehat team did not recover that WETH in time.
We are sharing an interim update regarding an exploit identified with @limitbreak Payment Processor V2, a NFT trading protocol maintained by the company Limit Break and which Magic Eden adopted to settle trades on EVM in 2024.
Magic Eden stopped using Payment Processor V2 in Oct…
— Magic Eden 🪄 (@MagicEden) September 25, 2026
Magic Eden stressed that no current listing on its platform was affected. The problem was the permission users had granted to a contract the marketplace no longer used.
That distinction matters because onchain approvals do not expire when a website changes strategy, disables a product or closes a marketplace. The permission lives on the blockchain until the wallet owner revokes it or the contract provides another way to shut it down.
At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives.
It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the… pic.twitter.com/Vue8TUyMD2
— Quit (@0xQuit) September 25, 2026
0xQuit said owners should revoke Payment Processor V2 approvals on Ethereum, Polygon and Base. ApeChain users should also revoke the affected V3 approval, and anyone whose NFTs were moved into the rescue wallet should revoke first before attempting to reclaim them.
Revoking an approval prevents future transfers; it cannot reverse a transfer that already happened. Users should rely on direct public updates from Magic Eden, Limit Break and 0xQuit rather than anyone offering recovery help in private messages.
The broader lesson reaches beyond NFTs. Wallet permissions can become forgotten attack surfaces long after the app that requested them has faded from view.
Crypto users routinely audit balances and transaction histories, but old approvals deserve the same attention. This exploit survived because the contract was old, not because the permission was gone.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
