Summary

  • Magic Eden has cautioned that NFTs listed on its now-defunct EVM marketplace from February to October 2024 might be vulnerable due to an exploit in Limit Break's Payment Processor V2.
  • According to Yuga Labs' 0xQuit, a whitehat initiative successfully rescued 23,155 NFTs valued at over $5.7 million, although 660 WETH could not be retrieved.
  • Users are advised to revoke contract approvals on Ethereum, Polygon, and Base, but this action will not recover tokens that have already been moved.

Although Magic Eden has shifted its focus away from Ethereum, some of its former users' NFTs remain at risk.

The marketplace issued a warning on Friday, indicating that NFTs listed on its EVM marketplace during the specified timeframe might be compromised due to a flaw in Payment Processor V2, an NFT trading system developed by Limit Break.

The EVM (Ethereum Virtual Machine) encompasses Ethereum and its compatible blockchains. Magic Eden utilized this contract for trading until it ceased operations in October 2024 and completely closed its EVM marketplace in early 2026.

"No active listings on Magic Eden were affected by this exploit," the company stated via X.

The vulnerability stems from lingering user approvals. When NFTs are listed, users typically grant contracts permission to manage these assets, and such permissions remain in effect until they are revoked.

Magic Eden is urging users who have listed or traded on the EVM marketplace to revoke the V2 contract's "approved for all" permissions across Ethereum, Polygon, and Base using Revoke.cash, while clarifying that revoking will not return any tokens that have already been transferred.

At 9AM EST today, someone exploited a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate Apewives.

It wasn't until over 12 hours later that someone alerted me, and upon investigation, I discovered that numerous NFTs were at risk of the… pic.twitter.com/Vue8TUyMD2

— Quit (@0xQuit) September 25, 2026

0xQuit, Vice President of Blockchain at Yuga Labs, reported that an attacker exploited the bug to steal various NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women, and 235 Desperate ApeWives. While Limit Break paused Payment Processor V3, which shared the same vulnerability, V2 could not be halted, necessitating a whitehat rescue operation where ethical hackers transfer at-risk assets to safety before malicious actors can act.

"In total, we managed to rescue 23,155 NFTs valued at over $5.7 million USD," 0xQuit stated. Owners will be able to reclaim their assets after revoking the necessary approvals, according to 0xQuit.

However, 660 wrapped Ethereum (WETH) that was exposed to a reverse version of the exploit could not be saved in time.

In February, Magic Eden discontinued support for Ethereum and Bitcoin to concentrate on Solana and its cryptocurrency casino, Dicey. The platform later phased out its multichain wallet.

This incident comes at a challenging time for the crypto community, as just yesterday, hackers managed to steal over $380 million in Ethereum and other digital assets from the Bitget exchange, marking the largest crypto hack of the year.

Daily Debrief Newsletter

Stay updated with the latest news stories, original features, podcasts, videos, and more.