Magic Eden says legacy approval flaw exposed NFTs as white hats rescued 23,155 tokens

Magic Eden says legacy approval flaw exposed NFTs as white hats rescued 23,155 tokens

N
News Editor
2026-09-27 07:48:59
Magic Eden said a legacy approval issue tied to Limit Break Payment Processor V2 left more than $5.7 million worth of NFTs exposed on its former EVM marketplace, with some assets already stolen before white hats intervened. According to the platform and Yuga Labs blockchain vice president 0xQuit, the attacker took 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives. Magic Eden said no active listings were affected because the issue stemmed from historical approvals granted by users who listed NFTs on its EVM marketplace between February and October 2024. Although the company stopped using Payment Processor V2 in October 2024 and shut its EVM marketplace in the first quarter of 2026, those approvals remained in place. White hats then recovered 23,155 NFTs, but 660 WETH tied to another exploit path could not be recovered in time. Magic Eden urged affected users to revoke Limit Break Payment Processor V2 approvals on Ethereum, Polygon and Base, and said rescued NFTs can only be safely returned after those approvals are revoked.

Magic Eden said a legacy approval contract on its former EVM marketplace exposed more than $5.7 million worth of NFTs to an exploit involving Limit Break Payment Processor V2. Some assets were stolen before white hats stepped in and recovered 23,155 NFTs.

Old approvals from 2024 remained in place

In an update posted on X, Magic Eden said NFTs listed on its EVM marketplace between February and October 2024 used Limit Break Payment Processor V2 as the settlement contract. The company stopped using that processor in October 2024 and shut down its EVM marketplace in the first quarter of 2026, but user approvals tied to those earlier transactions were not revoked at the same time.

Magic Eden said no active listings were affected, adding that current trading activity on the platform remained safe. The exposure was limited to users who had used the marketplace in the past.

Stolen assets included Meebits and Otherdeeds

According to Yuga Labs blockchain vice president 0xQuit, the attacker used the flaw to steal 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives.

0xQuit also said Limit Break paused Payment Processor V3, which was affected by the same bug. Payment Processor V2 could not be paused because of design constraints, leaving the vulnerability exposed.

White hats recovered 23,155 NFTs, but 660 WETH was lost

Because V2 could not be halted, white hats launched a rescue operation and recovered 23,155 NFTs valued at more than $5.7 million.

0xQuit said another way of abusing the same flaw could be used to drain WETH. That left 660 WETH at risk, worth about $1.5 million to $2 million at the then-current price, and the white-hat team was not fast enough to recover it.

Users are being told to revoke approvals

Magic Eden urged all users who listed NFTs on its EVM marketplace between February and October 2024 to revoke Limit Break Payment Processor V2 approvals on Ethereum, Polygon and Base. The company said rescued NFTs can be safely returned only after those approvals have been removed.

For that process, Magic Eden recommended approval management tools including Revoke.cash and DeBank so users can check whether their wallets still show approve records linked to the contract.

Incident highlights lingering approval risk in Web3

The case points to a recurring security problem in Web3: once a contract approval is granted, it stays valid until the user manually revokes it. Magic Eden had already stopped using the processor and even shut down the EVM marketplace, but the historical approval records still created an entry point for attackers.

The source article also referenced earlier cases including the 2024 CoW Swap front-end attack and an OpenSea approval flaw as examples of the same problem. Platform shutdowns and protocol upgrades do not automatically clear old user approvals.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.