Magic Eden disclosed on Friday that legacy approvals on its EVM marketplace left NFTs valued at more than $5.7 million exposed to an exploit in Limit Break’s Payment Processor V2. The NFT marketplace said it had stopped using the processor in October 2024 and shut down its EVM marketplace in the first quarter of 2026, adding that no live Magic Eden listings were impacted.
According to Yuga Labs Vice President of Blockchain 0xQuit, an attacker exploited the processor to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. Limit Break quickly paused Payment Processor V3, which was affected by the same bug, but V2 could not be paused. That left a whitehat operation as the main way to protect assets.
The whitehat effort rescued 23,155 NFTs worth more than $5.7 million. However, 0xQuit said a similar exploit could be used in reverse to steal WETH, and 660 WETH was at risk but could not be recovered in time.
Magic Eden advised users that NFTs listed on its EVM marketplace between roughly February and October 2024 may be affected. The platform recommended revoking the Payment Processor V2 approval on Ethereum, Polygon, and Base. Affected users will be able to reclaim rescued NFTs after revoking the exploitable approvals.
A separate report indicated that a whitehat moved 3,832 NFTs from hundreds of wallets to an address beginning with 0x71cF. Yuga Labs CEO Michael Figge said the issue had been discovered hours earlier and that 0xQuit was handling assets within the whitehat rescue. The NFTs are expected to be returned to original owners once the underlying risk is resolved, though Magic Eden has not yet disclosed the full cause or scope of the vulnerability.