Legacy approvals from Magic Eden's discontinued EVM marketplace exposed $5.7 million in NFTs to an exploit targeting Limit Break's Payment Processor V2. A whitehat rescue operation secured 23,155 NFTs before further theft, according to Magic Eden's official update on September 25, 2026.
Magic Eden stopped using Payment Processor V2 in October 2024 and shut down its EVM marketplace in the first quarter of 2026. Despite these actions, old approvals remained active, creating an attack surface for the vulnerability. No live Magic Eden listings were affected.
The vulnerability allowed an attacker to target NFTs whose owners had previously approved Payment Processor V2. Stolen assets included 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives before the whitehat intervention.
Limit Break paused Payment Processor V3 after discovering it was also affected by the same bug. Payment Processor V2 could not be paused, making the whitehat rescue the primary defense against assets exposed through legacy permissions.
A related path placed 660 WETH at risk, though the rescue team was unable to recover these funds.
Magic Eden advised users who listed NFTs on its EVM marketplace between February and October 2024 to manually revoke Payment Processor V2 approvals on Ethereum, Polygon, and Base networks. This action is necessary before reclaimed NFTs can safely return to user wallets.
The incident illustrates a core security principle: approvals on EVM networks do not automatically expire when a marketplace closes or replaces a contract. Users remain exposed unless they manually revoke permissions, making approval hygiene an ongoing requirement for those interacting with decentralized applications.
