Monday, September 28, 2026

Legacy Magic Eden Approvals Exposed in $2.8M Exploit

Neon-lit Ethereum NFT vault breached by a legacy contract flaw, glowing NFTs and WETH shards in a futuristic scene

A vulnerability in Limit Break’s legacy Payment Processor has allowed attackers to drain NFTs and approved tokens from wallets that retained old permissions after interacting with Magic Eden’s former EVM marketplace. In an official interim update, Magic Eden said it stopped using Payment Processor V2 in October 2024 and shut down its EVM marketplace in the first quarter of 2026. The affected security boundary is the Limit Break trading contract and lingering wallet approvals, not Magic Eden’s current marketplace or Ethereum itself.

The first known malicious transaction occurred on September 24 and removed 305 NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives. Security researcher 0xQuit, vice president of blockchain at Yuga Labs, subsequently coordinated a defensive operation that moved 23,155 exposed NFTs worth more than $5.7 million into custody. Those $5.7 million in assets were rescued rather than stolen and should not be included in the incident’s loss total.

Persistent Approvals Turned Into an Attack Path

The vulnerability went beyond dormant NFT listings. Payment Processor supports meta-transactions through trusted forwarders, and security analysis from Revoke.cash found that specially constructed calldata could make the protocol treat another wallet as a trade counterparty without that wallet signing a new transaction. Attackers could then combine that flaw with existing permissions to transfer NFTs at zero price or force wallets with token approvals to purchase attacker-controlled assets. The old approvals supplied access to user assets, while the Payment Processor flaw made that authority exploitable without fresh consent.

That distinction explains why canceling a listing or abandoning the marketplace did not remove the exposure. Onchain approvals persist until revoked, creating a risk similar to a recent BNB Chain router exploit that abused previously granted token allowances. A related pattern has appeared around legacy Notional V1 infrastructure, where retired code remained relevant to later attack attempts. Decommissioning a frontend does not automatically decommission the permissions and contracts users authorized while it was active.

Loss estimates also expanded after the initial rescue. 0xQuit reported that approximately 660 WETH could not be protected in time, initially worth around $1.7 million. Revoke.cash now tracks at least $2.8 million in stolen NFTs and tokens across Ethereum, Polygon, Base, Arbitrum and ApeChain, including subsequent attacks after details of the vulnerable contracts became public. That total remains separate from the NFTs secured by the whitehat operation.

V2 Remains Vulnerable as Users Revoke Approvals

Payment Processor V2 cannot be paused or upgraded, leaving deployed instances vulnerable wherever exploitable approvals remain. Limit Break paused Payment Processor V3 on other affected networks, but Revoke.cash says ApeChain remains an exception, with V3 usable there until November 30, 2026. The residual risk therefore sits primarily with wallets that still grant V2 or V3 authority, rather than with funds already moved into the rescue wallet.

The episode mirrors other cases where delegated permissions became the actual attack surface. A third-party Safe module exploit affecting Squid-linked wallets demonstrated how previously authorized execution rights can expose assets without compromising private keys, while the Aztec Connect Router incident similarly underscored the risks created by deprecated infrastructure. Legacy contracts remain economically relevant as long as they retain callable logic and users continue granting them authority over assets.

Magic Eden has urged users who interacted with its EVM marketplace between approximately February and October 2024 to revoke Payment Processor V2 approvals on Ethereum, Polygon and Base, while security researchers recommend checking Payment Processor permissions across every network. Revocation can prevent additional unauthorized transfers but cannot reverse assets already stolen. The next concrete milestone is the return of the 23,155 rescued NFTs after affected owners remove vulnerable approvals, alongside a final accounting of malicious drains across all affected chains.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.