Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit

Magic Eden warned that NFTs listed on its now-closed EVM marketplace between about February and October 2024 may be vulnerable to a bug in Limit Break's Payment Processor V2. A whitehat operation led by Yuga Labs' 0xQuit reportedly recovered 23,155 NFTs valued at more than $5.7 million, though 660 WETH exposed to a related exploit could not be recovered.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 36 minutes agoUpdated 36 minutes ago0 views
Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit

Why It Matters

The incident highlights lingering risks from smart-contract approvals that remain active after marketplaces stop using them, and shows how protocol bugs can endanger long-dormant listings across EVM chains. It also underscores operational limits: V2 could not be paused, forcing an emergency whitehat rescue rather than a simple protocol halt.

Key Facts

  • Affected contract: Limit Break Payment Processor V2
  • Potentially exposed listings timeframe: roughly February to October 2024
  • Recovered NFTs: 23,155
  • Estimated recovered value: north of $5.7 million USD
  • Irrecoverable funds: 660 WETH not recovered due to reverse exploit exposure

Magic Eden alerted users that NFTs listed on its EVM marketplace during roughly February through October 2024 could be exposed to an exploit in Limit Break's Payment Processor V2, an NFT settlement protocol. The marketplace stopped using the contract in October 2024 and ultimately closed its EVM marketplace in early 2026. Magic Eden said that no live Magic Eden listings were impacted, posting the statement on X.

The vulnerability stems from lingering "approved for all" permissions that users grant when listing NFTs; those approvals remain active until explicitly revoked. Magic Eden urged anyone who listed or traded on its EVM marketplace to revoke the V2 contract's permissions on Ethereum, Polygon and Base using a tool such as Revoke.cash, while noting that revoking cannot return tokens already moved.

Yuga Labs' vice president of blockchain, known as 0xQuit, reported that an attacker abused the V2 bug to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives. Because Payment Processor V2 could not be paused and V3 — which shared the flaw — was paused by Limit Break, a coordinated whitehat operation intervened and moved vulnerable assets to safety. 0xQuit said the rescue secured 23,155 NFTs valued at more than $5.7 million; however, 660 wrapped Ethereum (WETH) exposed to a reverse version of the exploit were not recovered.

The episode follows Magic Eden's earlier strategic moves: the marketplace removed Ethereum and Bitcoin support in February to concentrate on Solana and other products, and later wound down its multichain wallet. The notification comes amid a broader period of high-profile thefts in the crypto sector, including a separate breach of the Bitget exchange that led to losses exceeding $380 million.

Keep Reading