TL;DR
Magic Eden says old EVM marketplace approvals left more than $5.7 million worth of NFTs exposed to an exploit in Limit Break’s Payment Processor V2.
A whitehat rescue operation moved 23,155 vulnerable NFTs before they could be stolen.
Magic Eden says no live listings were affected, but users who interacted with the old marketplace should revoke lingering approvals.
An old smart contract can remain dangerous long after the product built around it has disappeared.
Magic Eden is dealing with exactly that problem after legacy approvals from its former EVM marketplace left thousands of NFTs exposed to a vulnerability in Limit Break’s Payment Processor V2.
The marketplace says more than $5.7 million worth of NFTs were at risk.
The Marketplace Was Closed, But The Approvals Were Still Live
Magic Eden stopped using Payment Processor V2 in October 2024 and later shut down its EVM marketplace.
That did not automatically revoke permissions users had previously granted to the contract.
When an attacker exploited the processor this week, those old approvals became relevant again.
The initial theft included assets from collections such as Meebits, Otherdeeds and World of Women.
Security researchers then realized a much larger number of wallets remained exposed.
A whitehat rescue operation ultimately secured 23,155 NFTs worth more than $5.7 million before they could be taken.
Users are expected to reclaim rescued assets after revoking the vulnerable approval.
Magic Eden says no active listings on its current products were affected.
Token Approvals Can Outlive The App That Asked For Them
The incident is a useful reminder of how wallet permissions work.
When a user gives a marketplace or protocol permission to transfer assets, that authorization can remain valid until it is explicitly revoked.
Closing a website does not necessarily remove it.
Changing marketplaces does not necessarily remove it.
Even abandoning a wallet interface does not alter what has already been approved onchain.
Magic Eden says users who interacted with its EVM marketplace during the affected period should revoke Payment Processor V2 permissions on supported networks including Ethereum, Polygon and Base.
Researchers also identified a related route that placed hundreds of WETH at risk, showing that the vulnerability was not limited to NFTs.
The technical exploit sits inside Limit Break’s processor rather than Magic Eden’s live marketplace.
But old Magic Eden approvals dramatically expanded the number of users potentially exposed.
Crypto security often focuses on what somebody is signing today.
This incident shows why the permissions granted years ago can matter just as much.
This article was written by the News Desk and edited by Samuel Rae.


