Magic Eden says old Ethereum NFT listings may still be exposed through Payment Processor V2 flaw

Magic Eden says old Ethereum NFT listings may still be exposed through Payment Processor V2 flaw

N
News Editor
2026-09-25 16:17:19
Magic Eden said NFTs listed on its EVM marketplace between roughly February and October 2024 may still be at risk because of a bug in Payment Processor V2, an NFT trading protocol built and maintained by Limit Break. The company said no active Magic Eden listings were affected, but older approvals tied to the contract may still remain in place. It urged anyone who listed or traded on its EVM marketplace to revoke the V2 contract’s "approved for all" permissions on Ethereum, Polygon, and Base through Revoke.cash. The warning followed disclosures from Yuga Labs Vice President of Blockchain 0xQuit, who said an attacker used the flaw to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. Because Payment Processor V2 could not be paused, a whitehat rescue operation was launched after Limit Break paused V3, which shared the same issue. According to 0xQuit, the effort secured 23,155 NFTs worth more than $5.7 million, though 660 WETH exposed to a reverse form of the exploit was not recovered in time. Magic Eden had already stopped using the contract in October 2024 and shut down its EVM marketplace in early 2026. The episode comes a day after Bitget lost more than $380 million in Ethereum and other crypto assets in what Decrypt described as the year’s largest crypto hack so far.

Magic Eden said some NFTs once listed on its EVM marketplace may still be exposed to an exploit, even though the platform has already moved away from Ethereum.

Magic Eden says old Ethereum NFT listings may still be exposed through Payment Processor V2 flaw 2

On Friday, the marketplace warned that NFTs listed between roughly February and October 2024 could be affected by a bug in Payment Processor V2, an NFT trading protocol built and maintained by Limit Break.

EVM refers to Ethereum and chains compatible with it. Magic Eden adopted the contract to settle trades in 2024, stopped using it that October, and shut its EVM marketplace entirely in early 2026.

"No live Magic Eden listings were impacted in this exploit," the company said on X.

Old approvals are the main risk

The issue stems from lingering approvals. When users list NFTs, they usually grant a contract permission to move those assets, and that permission remains active until it is revoked.

Magic Eden urged anyone who listed or traded on its EVM marketplace to revoke the V2 contract’s "approved for all" permissions on Ethereum, Polygon, and Base through Revoke.cash. The company also said revoking approvals will not bring back tokens that have already been moved.

Attackers took NFTs before a whitehat rescue began

Yuga Labs Vice President of Blockchain 0xQuit said an attacker exploited Payment Processor V2 at 9 AM EST and took 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives.

According to 0xQuit, the incident was not reported to him until more than 12 hours later. After digging into it, he concluded that a large number of NFTs were exposed to the same problem.

Limit Break paused Payment Processor V3, which had the same flaw, but V2 could not be paused. That led to a whitehat rescue operation, with friendly hackers moving vulnerable assets before attackers could reach them.

"All in all, we rescued 23,155 NFTs worth north of $5.7M USD," 0xQuit wrote. He added that owners will be able to reclaim those assets after revoking the approvals.

Still, 660 wrapped Ethereum, or WETH, tied to a reverse version of the exploit was not recovered in time.

Magic Eden had already pulled back from Ethereum

Magic Eden dropped Ethereum and Bitcoin support in February to focus on Solana and its crypto casino, Dicey. It later wound down its multichain wallet.

The warning arrives during a broader security crunch

The disclosure came as crypto users were already dealing with another major security breach. Just one day earlier, unknown hackers stole more than $380 million in Ethereum and other crypto assets from Bitget, in what Decrypt described as the biggest crypto hack of the year so far.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
2700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.