Magic Eden says retired approvals left $5.7 million in NFTs exposed to exploit

Magic Eden says retired approvals left $5.7 million in NFTs exposed to exploit

Magic Eden says old approvals left $5.7 million in NFTs exposed

Magic Eden said legacy approvals on its EVM marketplace left NFTs worth more than $5.7 million exposed to an exploit in Limit Break's Payment Processor V2. NFTs are unique digital assets recorded on a blockchain. An approval is a permission that lets a third-party contract move assets from a user's wallet.

The marketplace said no live Magic Eden listings were affected. It said it stopped using the processor in October 2024 and shut down its EVM marketplace in the first quarter of 2026.

Stolen NFTs and the rescued total

  • An attacker used the processor to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives, according to Yuga Labs Vice President of Blockchain 0xQuit.
  • A whitehat operation rescued 23,155 NFTs worth more than $5.7 million, 0xQuit said.
  • The rescue did not cover 660 WETH, or wrapped ether, which was also at risk.
  • Magic Eden said NFTs listed on its EVM marketplace between roughly February and October 2024 may be affected.

What Magic Eden said in its update

In a post on X, Magic Eden said its legacy EVM approvals created the exposure. It wrote that 'No live Magic Eden listings were impacted.'

The company also confirmed the timeline of the shutdown: it moved away from the processor in October 2024 and closed the EVM marketplace in the first quarter of 2026.

What 0xQuit reported about Limit Break's processors

0xQuit, Yuga Labs' Vice President of Blockchain, said the vulnerability surfaced after an attacker exploited the processor. He said Limit Break quickly paused Payment Processor V3, which had the same bug, but that V2 could not be paused.

That left a whitehat operation, meaning a rescue effort by friendly actors, as the main way to protect the assets, he said. He added that a similar exploit could be used 'in reverse' to steal WETH, and that 660 WETH was at risk but was not recovered in time.

What is confirmed

  • Magic Eden, the primary source here, confirmed that legacy EVM approvals exposed NFTs worth more than $5.7 million and that no live listings were affected.
  • Magic Eden confirmed when it stopped using the processor and when it shut down the EVM marketplace.
  • Magic Eden said affected listings date to roughly February through October 2024 and advised users to revoke the Payment Processor V2 approval on Ethereum, Polygon and Base.

What remains unclear

The source material does not name the attacker, does not say how many users were affected, and does not give a dollar value for the 660 WETH that was not recovered. It also does not say whether any of the stolen NFTs were returned.

Why old approvals can still be a risk

Approvals can stay active after a service is retired. In this case, even though Magic Eden's EVM marketplace is closed, the old approvals could still be used by an attacker until wallet owners revoke them. The rescue of 23,155 NFTs was reported by 0xQuit, while Magic Eden's own statement focused on the exposure and the advice to revoke approvals.

What happens next for affected users

Magic Eden advised users to revoke the Payment Processor V2 approval on Ethereum, Polygon and Base. It said users will be able to reclaim rescued NFTs after they revoke the exploitable approvals.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!