Crypto news report · source clearly identified

Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit

A flaw in Limit Break's Payment Processor V2 put old Magic Eden Ethereum listings at risk, prompting a whitehat rescue of more than 23,000 NFTs.

Magic Eden has alerted users that NFTs listed on its now‑closed EVM marketplace between roughly February and October 2024 may be vulnerable to an exploit in Limit Break’s Payment Processor V2.

Scope of the vulnerability

The issue stems from lingering "approved for all" permissions that remain active after a user lists an NFT. When the contract is exploited, it can move the listed assets without the owner’s consent.

White‑hat rescue operation

Yuga Labs’ blockchain lead, known as 0xQuit, reported that a white‑hat effort rescued 23,155 NFTs valued at over $5.7 million. The rescued assets include Meebits, Otherdeeds, World of Women, and Desperate ApeWives NFTs. Approximately 660 WETH remained unrecovered.

User actions required

Magic Eden advises anyone who listed or traded on its EVM marketplace to revoke the V2 contract’s approvals on Ethereum, Polygon, and Base using tools such as Revoke.cash. Revoking does not return assets that have already been moved.

Background on Magic Eden’s multichain shift

Magic Eden stopped using the Limit Break contract in October 2024 and fully shut its EVM marketplace in early 2026, having already discontinued Ethereum and Bitcoin support in February to focus on Solana and its Dicey casino platform.

Context of broader security concerns

The incident occurs amid a period of heightened crypto security incidents, including a recent hack of the Bitget exchange that resulted in the loss of more than $380 million.

Source & attribution

News Source

Publisher
Decrypt
Original date
September 25, 2026, 4:17 PM
Original headline
Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit
View original report ↗