Magic Eden announced on Friday that historical approvals on its EVM marketplace exposed over $5.7 million worth of NFTs to a security flaw within Limit Break’s Payment Processor V2.
Via a post on X, the NFT marketplace noted that it discontinued using the processor back in October 2024 and closed down its EVM marketplace during the first quarter of 2026. They stated that no active Magic Eden listings suffered any impact.
The security flaw came to light after a malicious actor leveraged the processor to make off with 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives, based on statements from Yuga Labs Vice President of Blockchain 0xQuit.
0xQuit pointed out that Limit Break swiftly halted Payment Processor V3, which was vulnerable to the exact same defect, but V2 lacked a pause function.
Consequently, executing a whitehat rescue mission became the primary method to secure the digital items, the VP noted, pointing out that this intervention successfully saved 23,155 NFTs valued above $5.7 million.
Nonetheless, the rescue operation failed to protect 660 WETH that faced exposure to a connected vulnerability.
As 0xQuit shared in an X post, they later found that a comparable exploit could function in reverse to drain WETH. They mentioned that 660 WETH remained vulnerable, which they sadly could not salvage in time.
Based on information from Magic Eden, collections posted on its EVM marketplace from roughly February through October 2024 might be impacted. The company recommended that users revoke the Payment Processor V2 authorization across Ethereum, Polygon, and Base.
In the meantime, community members can retrieve their saved NFTs once they have revoked the compromised approvals.
Originally published at https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874.