Magic Eden Legacy Approvals Exploited; Whitehat Rescues $5.7M in NFTs

1 hour ago 3 sources negative

Key takeaways:

  • Legacy NFT approvals pose DeFi risk; revoke stale permissions on Ethereum, Polygon, and Base.
  • Whitehat rescue of 23,155 NFTs shows intervention limits; 660 WETH loss stresses approval hygiene.
  • Meebits and Otherdeeds exposure signals blue-chip NFT holders must audit old marketplace approvals.

Magic Eden disclosed on Friday that legacy approvals on its EVM marketplace left NFTs valued at more than $5.7 million exposed to an exploit in Limit Break’s Payment Processor V2. The NFT marketplace said it had stopped using the processor in October 2024 and shut down its EVM marketplace in the first quarter of 2026, adding that no live Magic Eden listings were impacted.

According to Yuga Labs Vice President of Blockchain 0xQuit, an attacker exploited the processor to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. Limit Break quickly paused Payment Processor V3, which was affected by the same bug, but V2 could not be paused. That left a whitehat operation as the main way to protect assets.

The whitehat effort rescued 23,155 NFTs worth more than $5.7 million. However, 0xQuit said a similar exploit could be used in reverse to steal WETH, and 660 WETH was at risk but could not be recovered in time.

Magic Eden advised users that NFTs listed on its EVM marketplace between roughly February and October 2024 may be affected. The platform recommended revoking the Payment Processor V2 approval on Ethereum, Polygon, and Base. Affected users will be able to reclaim rescued NFTs after revoking the exploitable approvals.

A separate report indicated that a whitehat moved 3,832 NFTs from hundreds of wallets to an address beginning with 0x71cF. Yuga Labs CEO Michael Figge said the issue had been discovered hours earlier and that 0xQuit was handling assets within the whitehat rescue. The NFTs are expected to be returned to original owners once the underlying risk is resolved, though Magic Eden has not yet disclosed the full cause or scope of the vulnerability.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.