Broken rusted chain beside the Ethereum symbol illustrating an exposed legacy NFT approval

Old Magic Eden Approvals Exposed 23,000 NFTs Before Whitehat Rescue

• September 25, 2026 3:13 pm • Comments

Magic Eden stopped using one of its old Ethereum payment contracts nearly two years ago. The approvals granted to that contract did not stop with it.

That gap left more than 23,000 NFTs exposed when an attacker found a flaw in Limit Break’s Payment Processor V2 this week. A whitehat rescue prevented a much larger loss, but the episode is a sharp warning for anyone who assumes an old marketplace approval disappears when the marketplace moves on.

Decrypt reported that Magic Eden used Payment Processor V2 to settle EVM trades in 2024, stopped using it that October and shut its EVM marketplace in early 2026. Users who listed NFTs between roughly February and October 2024 could still have “approve for all” permissions attached to the contract.

The exploit began with 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives taken through the flaw. Limit Break could pause its newer V3 contract, which had a similar weakness, but V2 could not be paused.

That forced defenders to move the exposed assets before the attacker could. Yuga Labs Vice President of Blockchain 0xQuit said the operation rescued 23,155 NFTs worth more than $5.7 million, with owners able to reclaim them after revoking the dangerous approvals.

The rescue was not complete. Another version of the exploit put 660 wrapped Ethereum at risk, and the whitehat team did not recover that WETH in time.

Magic Eden stressed that no current listing on its platform was affected. The problem was the permission users had granted to a contract the marketplace no longer used.

That distinction matters because onchain approvals do not expire when a website changes strategy, disables a product or closes a marketplace. The permission lives on the blockchain until the wallet owner revokes it or the contract provides another way to shut it down.

0xQuit said owners should revoke Payment Processor V2 approvals on Ethereum, Polygon and Base. ApeChain users should also revoke the affected V3 approval, and anyone whose NFTs were moved into the rescue wallet should revoke first before attempting to reclaim them.

Revoking an approval prevents future transfers; it cannot reverse a transfer that already happened. Users should rely on direct public updates from Magic Eden, Limit Break and 0xQuit rather than anyone offering recovery help in private messages.

The broader lesson reaches beyond NFTs. Wallet permissions can become forgotten attack surfaces long after the app that requested them has faded from view.

Crypto users routinely audit balances and transaction histories, but old approvals deserve the same attention. This exploit survived because the contract was old, not because the permission was gone.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.