Crypto news report · source clearly identified
Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit
A flaw in Limit Break's Payment Processor V2 put old Magic Eden Ethereum listings at risk, prompting a whitehat rescue of more than 23,000 NFTs.

Magic Eden has alerted users that NFTs listed on its now‑closed EVM marketplace between roughly February and October 2024 may be vulnerable to an exploit in Limit Break’s Payment Processor V2.
Scope of the vulnerability
The issue stems from lingering "approved for all" permissions that remain active after a user lists an NFT. When the contract is exploited, it can move the listed assets without the owner’s consent.
White‑hat rescue operation
Yuga Labs’ blockchain lead, known as 0xQuit, reported that a white‑hat effort rescued 23,155 NFTs valued at over $5.7 million. The rescued assets include Meebits, Otherdeeds, World of Women, and Desperate ApeWives NFTs. Approximately 660 WETH remained unrecovered.
User actions required
Magic Eden advises anyone who listed or traded on its EVM marketplace to revoke the V2 contract’s approvals on Ethereum, Polygon, and Base using tools such as Revoke.cash. Revoking does not return assets that have already been moved.
Background on Magic Eden’s multichain shift
Magic Eden stopped using the Limit Break contract in October 2024 and fully shut its EVM marketplace in early 2026, having already discontinued Ethereum and Bitcoin support in February to focus on Solana and its Dicey casino platform.
Context of broader security concerns
The incident occurs amid a period of heightened crypto security incidents, including a recent hack of the Bitget exchange that resulted in the loss of more than $380 million.
Source & attribution
News Source
- Publisher
- Decrypt
- Original date
- September 25, 2026, 4:17 PM
- Original headline
- Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit