Latest News

Magic Eden Legacy Approvals Expose $5.7M in NFTs as Limit…

Magic Eden said legacy permissions from its former EVM marketplace exposed more than $5.7 million of NFTs to an exploit in Limit Break’s Payment Processor V2, showing that wallet approvals can remain dangerous long after a marketplace stops using the underlying contract.The marketplace said Friday that no live Magic Eden listings were affected. It stopped using Payment Processor V2 in October 2024 and closed its EVM marketplace in the first quarter of 2026, but approvals granted by users while the integration was active remained on-chain.Yuga Labs Vice President of Blockchain 0xQuit said a whitehat operation ultimately secured 23,155 NFTs worth more than $5.7 million. A separate version of the vulnerability also placed roughly 660 WETH at risk, which the rescue operation was not fast enough to recover.

How Did a Closed Marketplace Leave Assets Exposed?

The problem was not an active Magic Eden listing. It was the permission users had previously given Payment Processor to move assets from their wallets.When an NFT owner grants a marketplace contract an “approved for all” permission, that authorization can remain active until the user explicitly revokes it. Closing a listing, migrating to another marketplace or even shutting down the original trading interface does not necessarily remove the underlying blockchain approval.Magic Eden said NFTs listed on its EVM marketplace between roughly February and October 2024 could be affected and urged former users to revoke Payment Processor V2 permissions on Ethereum, Polygon and Base.The exposure survived a major change in Magic Eden’s own business. FinanceFeeds reported in February that the company was winding down its Bitcoin and EVM marketplaces as part of a strategic refocus.

Investor Takeaway

The incident shows that shutting down a product does not automatically eliminate smart-contract exposure. Legacy approvals can outlive the platform that originally requested them.

What Was Stolen and What Did the Whitehat Operation Save?

According to 0xQuit’s account of the incident, an attacker initially exploited Payment Processor V2 to take 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives.After investigating the activity, 0xQuit found that substantially more assets were exposed. Limit Break was able to pause Payment Processor V3, which contained the same vulnerability, but V2 could not be paused. The response therefore shifted to moving vulnerable NFTs into protective custody before another attacker could take them.The operation rescued 23,155 NFTs valued at more than $5.7 million, 0xQuit said. Owners are expected to regain control of the assets after removing the vulnerable approvals so that returned NFTs cannot immediately be taken again.The problem extended beyond NFTs. 0xQuit said researchers later discovered that a similar technique could be used “in reverse” against WETH approvals. Approximately 660 WETH was exposed and could not be secured in time. Public blockchain analysis has since indicated that hundreds of WETH moved from affected wallets, although Magic Eden and Limit Break have not published a final accounting of those losses.

Investor Takeaway

The $5.7 million figure represents rescued NFTs, not confirmed losses. The eventual financial impact will depend on the WETH and NFT losses that remain unrecovered after the incident is fully reconciled.

Why Are Old Token Approvals Becoming a Larger Security Risk?

The exploit adds to a recurring category of crypto attacks that do not require stealing a private key. Instead, attackers abuse permissions a wallet legitimately granted to a contract months or years earlier.FinanceFeeds recently examined tools for identifying unsafe or forgotten smart-contract approvals, noting that unlimited permissions can leave assets exposed long after a user stops interacting with a protocol.A similar issue appeared in January when the SwapNet exploit exposed users who had previously approved its router. That attack also illustrated how a vulnerability in an approved contract can turn an otherwise legitimate permission into a route for removing assets without obtaining a new signature from the holder.

What Happens Next for Affected Wallets?

Magic Eden has advised users who interacted with its former EVM marketplace to check and revoke Payment Processor V2 approvals across Ethereum, Polygon and Base. Users should not assume cancelling an old listing is sufficient.The remaining questions are operational. Limit Break has not yet published a detailed public postmortem explaining the vulnerability, while the final amount taken from affected wallets remains unsettled. Investors will also be watching the NFT return process, whether additional assets are identified as exposed and whether any compensation or recovery plan emerges for WETH that left user wallets.The episode follows another Yuga Labs-linked whitehat intervention earlier this year, when 0xQuit helped rescue high-value NFTs during the Flooring Protocol exploit.

Investor Takeaway

The immediate risk falls on wallets that still maintain the affected approvals. The longer-term issue is whether marketplaces adopt stronger processes for retiring permissions when contracts or entire products are discontinued.