Magic Eden has warned that legacy wallet approvals connected to a discontinued EVM marketplace feature left more than $5.7 million worth of NFTs exposed to an exploit involving Limit Break’s Payment Processor V2, prompting a whitehat operation that secured 23,155 tokens before attackers could take them.
The marketplace said in a Friday post on X that it had stopped using Payment Processor V2 in October 2024 and closed its EVM marketplace during the first quarter of 2026. Yet approvals granted by users while the processor was active remained valid on Ethereum, Polygon and Base, creating an attack path even after the marketplace itself had shut down.
Magic Eden said no active listings on its platform were affected. The exposure applies to NFTs listed on its EVM marketplace from roughly February through October 2024, when users may have approved the processor to move assets as part of a sale.
Exploit led to thefts before rescue operation
The flaw surfaced after an attacker used the Payment Processor vulnerability to take NFTs from several prominent collections, according to 0xQuit, vice president of blockchain at Yuga Labs. The stolen assets included 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives.
0xQuit said Payment Processor V3 contained the same vulnerability but was paused, preventing further use through that version. Payment Processor V2 could not be paused, leaving previously granted permissions active and forcing affected users to revoke them individually.
A whitehat group then used the same vulnerable approval route to move exposed NFTs into protective custody. The operation recovered 23,155 NFTs with a stated value above $5.7 million, according to 0xQuit. Users who revoke the affected Payment Processor V2 permissions will be able to reclaim the protected NFTs, Magic Eden said, though it did not give a date for the recovery process.
The episode illustrates a persistent risk in Ethereum-compatible NFT markets: closing an application or removing a smart-contract integration does not automatically cancel permissions that wallet owners granted years earlier. Those approvals remain recorded on-chain until users revoke them, and a flaw in an approved contract can give an attacker the ability to transfer assets without obtaining a new signature from the wallet owner.
WETH losses were not recovered
The rescue operation did not secure 660 wrapped Ether, or WETH, that 0xQuit said was vulnerable through a related method. He said the funds could be taken through a similar exploit conducted in reverse and were not recovered before the attack path was identified and addressed.
Separate wallet activity tracked by Cirrus showed thousands of NFTs moving from hundreds of wallets during the incident. Cirrus said roughly 3,832 digital items left personal wallets in a coordinated period of unusual on-chain activity.
Cirrus also reported that 530.7 WETH was taken from 911 tracked wallets, valued at roughly $1.43 million at the market price used in its assessment. The tracker said 10 heavily exposed wallets accounted for 196 WETH of those losses. Those figures concern assets that were removed from affected wallets and are separate from the NFTs placed into the whitehat recovery effort.
The distinction between NFTs and WETH matters for affected users. NFTs transferred by the whitehat operation are expected to be returned after owners remove the vulnerable approval. WETH taken through the related exploit was not included in that rescue, based on the disclosures from 0xQuit and Magic Eden.
Old approvals can outlast marketplaces
NFT marketplaces commonly rely on token approvals that let a designated smart contract transfer a token when a sale is executed. The arrangement reduces the number of signatures needed during a trade, but it also means the approved contract retains authority until the approval is revoked or replaced.
Hardware wallets do not neutralize that risk once an approval has already been signed. A hardware device protects a wallet’s private key from being extracted, but a malicious or compromised approved contract can act under permissions previously granted by the wallet owner.
Magic Eden advised users who listed NFTs on its EVM marketplace during the relevant 2024 period to revoke Payment Processor V2 approvals on Ethereum, Polygon and Base. The company’s warning is aimed at wallets that interacted with the marketplace’s former EVM trading flow, rather than every wallet that has used Magic Eden’s services.
The incident also places greater scrutiny on how NFT platforms communicate the status of old contract permissions after retiring a product. A marketplace can stop operating, while the approval relationships created during its active period continue to exist independently on the blockchain. In this case, the vulnerable V2 processor remained capable of interacting with assets held in wallets that had never removed its access.
Users with older marketplace activity should review token approvals across each network where they traded. Revoking unused permissions prevents a previously authorized contract from moving NFTs or tokens if a vulnerability is later discovered. For Magic Eden users affected by this event, that revocation is also the condition for reclaiming NFTs saved by the whitehat operation.
Strengthen your crypto defenses by reading what to learn from crypto security breaches and applying lessons from major exploit incidents.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
