Magic Eden Legacy Approvals Exploited; White Hats Rescue 23,155 NFTs

Magic Eden Legacy Approvals Exploited; White Hats Rescue 23,155 NFTs

Old approvals tied to Magic Eden's Ethereum marketplace drained wallets

Attackers exploited Limit Break's Payment Processor contracts to take NFTs and other tokens from wallets that still had old Magic Eden approvals in place. An approval is a permission a wallet owner gives a contract to move their assets. A white-hat rescue followed across Ethereum and ApeChain, with white hats being security helpers who try to move assets out of harm's way before thieves can take them.

Yuga Labs' vice president of blockchain, 0xQuit, said on Sept. 25 that the rescue team secured 23,155 NFTs, which he valued at more than $5.7 million.

Those rescued assets are separate from the losses to attackers. Revoke.cash's incident tracker estimated that at least $2.8 million had been stolen as of 8 a.m. ET that day, and it said attacks were still ongoing at that point.

Key numbers from the theft and the rescue

  • 23,155 NFTs were secured, valued by 0xQuit at more than $5.7 million.
  • At least $2.8 million was estimated stolen as of 8 a.m. ET on Sept. 25, according to Revoke.cash's incident tracker, which noted attacks were still continuing then.
  • Magic Eden said NFTs listed through its Ethereum-compatible marketplace from about February through October 2024 could be affected.
  • An Ethereum transaction linked by Revoke.cash records 70 NFTs moving from one wallet to the transaction's initiating address on Sept. 24, supporting part of the initial theft described by Quit.

What Magic Eden confirmed about the affected listings

Magic Eden confirmed the exploit and identified Limit Break as the owner and maintainer of the affected protocol. The marketplace said NFTs listed through its Ethereum-compatible marketplace from roughly February through October 2024 could be affected. It stopped using Payment Processor V2 in October 2024 and closed its EVM marketplace in the first quarter of 2026.

"No live Magic Eden listings were impacted in this exploit," the company said. Even so, the old permissions stayed active after the marketplace stopped using the contract, which left holders exposed even if they had no current listing.

How the flaw let attackers take assets, according to Revoke.cash

Revoke.cash said the flaw lets an attacker impersonate a wallet as a trade counterparty without that wallet's signature. Existing approvals then allow NFTs to be taken through zero-price trades, or approved tokens to be spent on an attacker's worthless NFT. It added that canceling listings or invalidating trading signatures does not remove that exposure.

Which approvals holders still need to revoke

Quit said Limit Break paused Payment Processor V3 after being alerted, but V2 cannot be paused. V3 on ApeChain also could not be paused at the time, so a rescue was needed there as well.

His revocation notice lists two contracts:

  • Payment Processor V2 on Ethereum: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834
  • Payment Processor V3 on ApeChain: 0x9a1D00000000fC540e2000560054812452eB5366

Magic Eden told users to filter for the V2 address on Revoke.cash and revoke every NFT "approved for all" entry, then repeat the check on Polygon and Base. Revoke.cash's wider warning covers approvals to either affected contract on any chain, including WETH and other token allowances, not just NFT permissions. It also said most of the stolen funds came from token approvals that the rescue could not protect in time.

Quit identified the rescue custody address as 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33. He said owners would be able to claim their NFTs back "after revoking the exploitable approvals." Revoking protects assets still in a holder's wallet, but it does not return assets that have already moved.

What is confirmed and what is still unclear

Confirmed: Magic Eden acknowledged the exploit and named Limit Break as the protocol's owner and maintainer; Quit reported the rescue of 23,155 NFTs and the custody address; Revoke.cash reported the flaw, the $2.8 million minimum loss estimate, and the Sept. 24 transaction moving 70 NFTs; Magic Eden and Revoke.cash published the steps and contracts involved in revoking permissions.

Unclear: the full size of the losses, because Revoke.cash's figure was a minimum estimate taken at 8 a.m. ET while attacks were still underway. The more than $5.7 million value placed on the rescued NFTs is Quit's own valuation, not an independently confirmed figure. The sources also do not say whether the attackers have been identified or whether any stolen assets have been recovered.

Why this matters for NFT holders

Approvals can stay live long after a marketplace stops using a contract, so a wallet may still be exposed even with nothing listed for sale. Canceling a listing is not the same as removing a permission. Removing an approval only protects assets still in the wallet; it does not bring back assets that have already been taken.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!