NewsCryptoMagic Eden Warns Old Ethereum NFT Listings Exposed to Limit Break Payment Processor Exploit

Magic Eden Warns Old Ethereum NFT Listings Exposed to Limit Break Payment Processor Exploit

Author: Decrypt·

Key Takeaways

  • •An attacker abused a bug in Limit Break's Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives, with the theft going unreported for more than 12 hours.
  • •A whitehat operation led by Yuga Labs Vice President of Blockchain 0xQuit rescued 23,155 NFTs worth over $5.7 million, and owners can reclaim the tokens after revoking their approvals.
  • •Payment Processor V2 could not be paused unlike V3, leaving user-side revocations as the only way to close the exposure, and 660 WETH exposed to a reverse version of the exploit could not be saved.
  • •Magic Eden urged anyone who listed or traded on its EVM marketplace to revoke the V2 contract's 'approved for all' permissions on Ethereum, Polygon, and Base using Revoke.cash.
  • •Magic Eden adopted the Limit Break contract to settle trades in 2024, stopped using it that October, and shut down its EVM marketplace in early 2026 after dropping Ethereum and Bitcoin support to focus on Solana.
Magic Eden Warns Old Ethereum NFT Listings Exposed to Limit Break Payment Processor Exploit

Magic Eden may have moved on from Ethereum, but the fallout from its multichain era is still being felt by some of its former users.

The marketplace warned on Friday that NFTs listed on its now-shuttered EVM marketplace between roughly February and October 2024 could be exposed to an exploit in Payment Processor V2, an NFT trading protocol built and maintained by Limit Break. EVM refers to Ethereum and the blockchains compatible with it. Magic Eden adopted the Limit Break contract to settle trades in 2024, stopped using it that October, and shut down its EVM marketplace entirely in early 2026.

"No live Magic Eden listings were impacted in this exploit," the company said on X.

The problem lies in lingering token approvals. When users list NFTs for sale, they typically grant a smart contract permission to move the assets, and that permission stays active until it is manually revoked. Because those permissions are granted from users' own wallets, shutting down a marketplace doesn't cancel them — which is why trades settled before Magic Eden exited EVM chains can still pose a risk. Magic Eden urged anyone who listed or traded on its EVM marketplace to revoke the V2 contract's "approved for all" permissions — a blanket authorization that lets a contract move any of a wallet's NFTs rather than a single token at a time — on Ethereum, Polygon, and Base using the token-approval management tool Revoke.cash. It cautioned that revoking won't return tokens that have already moved.

Whitehat operation rescues 23,155 NFTs

Yuga Labs Vice President of Blockchain 0xQuit laid out the incident in a post on X, reporting that an attacker abused the bug to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. Meebits and Otherdeeds are both collections under the Yuga Labs umbrella.

"At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives. It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the…" pic.twitter.com/Vue8TUyMD2

— Quit (@0xQuit) September 25, 2026

Because the theft went unreported for more than 12 hours, 0xQuit said he only discovered the broader exposure upon digging into the incident.

Limit Break paused Payment Processor V3, which contained the same flaw, but V2 could not be paused — leaving no protocol-level off switch and making user-side revocations the only way to close the exposure. That forced a whitehat rescue — an operation in which friendly hackers move vulnerable assets to safety before attackers can reach them.

"All in all, we rescued 23,155 NFTs worth north of $5.7M USD," 0xQuit wrote. Owners will be able to reclaim the rescued tokens after revoking their approvals, according to 0xQuit.

Not everything could be recovered, however. 660 wrapped Ethereum (WETH), a tokenized form of ETH commonly used in NFT trading, exposed to a reverse version of the exploit was not saved in time.

Magic Eden's retreat from Ethereum and Bitcoin

Magic Eden dropped Ethereum and Bitcoin support in February to double down on Solana and its crypto casino, Dicey, as the company announced at the time. It later wound down its multichain wallet.

The episode lands at a rough time for crypto users. Just one day earlier, unknown hackers stole more than $380 million in Ethereum and other crypto assets from the Bitget exchange in what is now the biggest crypto hack of the year, as Decrypt reported.