Magic Eden Recovers $5.7M in NFTs After Limit Break Exploit
Security

Magic Eden Recovers $5.7M in NFTs After Limit Break Exploit

September 25, 20263 min read

Magic Eden warned users about a flaw in the Payment Processor V2 protocol that exposed old NFT listings on Ethereum. Limit Break built the contract, and an attacker used it to pull out tokens before a rescue operation began. The risk had been sitting there for two years.

A Flaw in Limit Break's Contract

Magic Eden started out as a Solana-first NFT marketplace before later adding support for Ethereum, Bitcoin, and other chains. The company remains one of the largest players in the NFT space today, even as its focus has shifted more toward prediction markets and crypto gambling in recent years.

Magic Eden's EVM marketplace ran on Payment Processor V2 for settling trades from roughly February to October 2024. The company switched to a newer contract that same year, then in February 2026 dropped Bitcoin and Ethereum support on its marketplace entirely. It later wound down its multichain wallet too, settling fully on Solana and its own crypto casino, Dicey.

The core issue is that "approved for all" permissions, granted to the contract whenever someone lists an NFT, stay active until a user revokes them by hand. Grant it once, and it lives forever unless someone remembers to cancel it. Those old approvals gave the attacker a way into tokens listed as far back as two years ago. The contract could still technically move someone's NFTs, even if that person had long forgotten about the listing.

Magic Eden said no live listings on its marketplace were at risk. The exposure only applied to positions owners never closed out or revoked. Blanket wallet permissions like this one have tripped up the NFT industry before. One forgotten signature is enough for an attacker to reach an entire collection, even after the marketplace that issued it has shut down.

A Whitehat Rescue Operation

On Friday, September 25, Yuga Labs' Vice President of Blockchain, known as 0xQuit, said on X that the attack started at 9 AM Eastern time. The attacker exploited the bug in Payment Processor V2 and grabbed a batch of rare collectibles:

  • 10 Meebits
  • 50 Otherdeeds
  • 10 World of Women NFTs
  • 235 Desperate ApeWives

Someone flagged the exploit more than twelve hours later. The attacker had that whole window to work unnoticed, which is part of why the scale of the theft grew so large. Limit Break managed to pause Payment Processor V3, which carried the same flaw, but V2 could not be paused. Every minute counted.

A whitehat team started moving vulnerable NFTs to safety before attackers could reach them, pulling tokens out of other people's wallets without asking, just to keep them away from the exploit. The industry calls this protective custody. Rescuers take control of the asset before thieves can.

0xQuit said rescuers moved 23,155 NFTs worth more than $5.7 million into protective custody.

Not Everything Made It Out

The rescue wasn't perfect. 660 wrapped Ethereum tokens caught up in a reverse version of the same bug weren't recovered in time and are considered lost. Owners of the rescued NFTs will be able to reclaim them once they revoke the outdated contract permissions.

Rescue operations like this one are becoming a more common tool in crypto security. Teams like White Hat act without any official mandate, relying only on reputation and speed. That doesn't replace a smart contract audit, but it gives asset owners a shot they simply didn't have a few years ago.

The episode landed in an already rough week for crypto. A day earlier, hackers drained more than $380 million from Bitget's hot wallets, making it the biggest crypto hack of 2026. Two major incidents in two days pushed some traders to check their own wallet hygiene.

"No live Magic Eden listings were impacted in this exploit."

- from Magic Eden's official statement on X, September 25, 2026

What NFT Owners Should Do Now

Magic Eden urged anyone who ever listed on its EVM marketplace to check Payment Processor V2 permissions through Revoke.cash and cancel them on Ethereum, Polygon, and Base. The company noted that revoking a permission won't bring back tokens already stolen, it only blocks the door for future attacks. The check takes a couple of minutes.

Security researchers recommend reviewing wallet permissions on a regular schedule, not just after another hack makes headlines. The incident itself is unlikely to affect Magic Eden's daily operations, since the company wound down its EVM business back in winter. But for NFT owners still holding old approvals in their wallets, the risk stays real until they check and revoke them by hand. A two-year-old forgotten approval cost someone a whole collection this week.

Comments

Your email address will not be published. Required fields are marked *

or verify by email