TL;DR:
- Magic Eden said legacy EVM approvals exposed $5.7 million in NFTs through a Limit Break Payment Processor V2 vulnerability, although no live listings were affected.
- A whitehat operation rescued 23,155 NFTs before further theft, while 660 WETH tied to a related exploit remained unrecovered.
- Users who listed NFTs between February and October 2024 should revoke Payment Processor V2 approvals on Ethereum, Polygon and Base before reclaimed assets return safely.
Magic Eden says legacy approvals from its discontinued EVM marketplace left $5.7 million in NFTs exposed to an exploit affecting Limit Break’s Payment Processor V2. In an official update, the marketplace said it stopped using the processor in October 2024 and shut its EVM marketplace in Q1 2026. No live Magic Eden listings were affected, but old approvals remained active after the marketplace moved on, leaving old permissions as an attack surface.
We are sharing an interim update regarding an exploit identified with @limitbreak Payment Processor V2, a NFT trading protocol maintained by the company Limit Break and which Magic Eden adopted to settle trades on EVM in 2024.
Magic Eden stopped using Payment Processor V2 in Oct…
— Magic Eden 🪄 (@MagicEden) September 25, 2026
Legacy Approvals Turned Into a Persistent Security Risk
The vulnerability allowed an attacker to target NFTs whose owners had previously approved Payment Processor V2. Assets stolen before the response included 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives. The incident shows why persistent token and NFT approvals can remain dangerous long after users stop interacting with a contract. Similar approval-linked exploits have highlighted how permissions can outlive the product experience that requested them.

Limit Break paused Payment Processor V3 after discovering it was affected by the same bug, but V2 could not be paused. That left a whitehat rescue as the main defense for assets still exposed through legacy permissions. The operation secured 23,155 NFTs worth more than $5.7 million before further theft. The rescue limited the NFT damage, but it did not eliminate the underlying approval problem. The response resembles other whitehat NFT recoveries where rapid intervention protected assets before wider losses.
A related path also placed 660 WETH at risk, and the rescue team was not fast enough to recover those funds. Magic Eden advised users who listed NFTs on its EVM marketplace between roughly February and October 2024 to revoke Payment Processor V2 approvals on Ethereum, Polygon and Base. Users must revoke the vulnerable approval before reclaimed NFTs can safely return to their wallets. The warning reinforces the importance of reviewing stale contract permissions after an application has been deprecated.
The episode leaves Magic Eden dealing with security exposure created by infrastructure it stopped using nearly two years earlier. Approvals on EVM networks do not automatically disappear when a marketplace closes or replaces a contract, meaning users can remain exposed unless permissions are manually revoked. The central lesson is that deprecating infrastructure does not revoke authority already granted by wallets. That authorization risk has surfaced in other Ethereum contract exploits, making approval hygiene an ongoing security requirement.