Magic Eden Says Legacy Approvals Exposed $5.7M In NFTs
A whitehat operation moved 23,155 NFTs to safety after an exploit targeted Limit Break’s Payment Processor V2. Magic Eden said no live listings were affected.

Magic Eden said legacy approvals from its former EVM marketplace exposed NFTs to a vulnerability in Limit Break’s Payment Processor V2, triggering a whitehat rescue of 23,155 assets valued at more than $5.7 million.
The initial attack occurred at about 9 a.m. ET (1 p.m. UTC) Thursday, when an attacker took 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives.
Magic Eden stopped using Payment Processor V2 in October 2024 and shut down its EVM marketplace in the first quarter of 2026. However, NFTs listed between roughly February and October 2024 may still have retained “approve for all” permissions, allowing the contract to transfer them until users revoke those permissions.
Limit Break paused Payment Processor V3 after the vulnerability emerged, but V2 could not be paused. The whitehat operation moved the exposed NFTs to safety, while 660 WETH connected to a related exploit remained unrecovered.
Magic Eden said no live listings were affected. Users who previously listed or traded NFTs through the former marketplace should review and revoke Payment Processor V2 approvals on Ethereum, Polygon and Base before attempting to reclaim rescued assets.


