Magic Eden's legacy approvals from its discontinued EVM marketplace exposed $5.7 million in NFTs to an exploit in Limit Break's Payment Processor V2, a protocol Magic Eden used to settle trades on EVM networks in 2024.
The marketplace stopped using Payment Processor V2 in October 2024 and shut down its EVM marketplace in the first quarter of 2026. Despite these actions, old token approvals remained active, creating an attack surface for assets whose owners had previously granted permissions to the processor.
No live Magic Eden listings were affected. The vulnerability stemmed from the persistence of token and NFT approvals on EVM networks—permissions outlived the product that requested them, leaving users exposed long after the contract was deprecated.
An attacker targeted NFTs with prior Payment Processor V2 approvals. Assets stolen before whitehat intervention included 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives.
Limit Break paused Payment Processor V3 after discovering it contained the same bug. Payment Processor V2 could not be paused, making a whitehat rescue operation the primary defense for exposed assets.
The whitehat team secured 23,155 NFTs valued at more than $5.7 million, preventing further theft. A related vulnerability placed 660 WETH at risk, but the rescue team was unable to recover these funds before they were stolen.
Magic Eden advised users who listed NFTs on its EVM marketplace between February and October 2024 to revoke Payment Processor V2 approvals on Ethereum, Polygon, and Base. Users must manually revoke these permissions before reclaimed NFTs can safely return to their wallets.
The incident demonstrates that deprecating infrastructure does not automatically revoke previously granted wallet authority. This authorization risk has surfaced in other Ethereum contract exploits, making regular approval hygiene essential for on-chain participants.