Magic Eden said legacy wallet approvals tied to its former EVM marketplace left more than $5.7 million worth of NFTs exposed after Limit Break’s Payment Processor V2 was exploited this week.
The company said it stopped using the processor in October 2024 and later shut down the marketplace, but permissions previously granted by users stayed active onchain. A whitehat operation then moved to secure affected assets before they could be stolen.
Old permissions became a new risk
According to Magic Eden, the issue did not come from its current products but from approvals users had given in the past to Limit Break’s Payment Processor V2. Those permissions remained valid even after Magic Eden stopped using the contract and closed its EVM marketplace.
When the processor was exploited this week, those lingering approvals created a wider attack surface. Magic Eden said the value of NFTs left at risk through those legacy permissions exceeded $5.7 million.
Initial thefts hit major collections
The first reported thefts included NFTs from well-known collections such as Meebits, Otherdeeds and World of Women. After that, security researchers determined that many more wallets were still exposed through the same approval path.
A whitehat rescue effort was launched and ultimately secured 23,155 NFTs, which Magic Eden said were worth more than $5.7 million. The company said users will be able to reclaim those rescued assets after revoking the vulnerable approval.
Magic Eden says live marketplace activity was not affected
Magic Eden said no active listings on its current products were impacted. It attributed the problem to the vulnerable Payment Processor V2 contract rather than to its live marketplace infrastructure.
Even so, the company said users who interacted with its EVM marketplace during the affected period should review and revoke Payment Processor V2 approvals. The networks mentioned were Ethereum, Polygon and Base.
Why dormant approvals still matter
The episode highlights a basic feature of onchain permissions: an approval can continue to authorize transfers until it is explicitly revoked. Shutting down a website or discontinuing a product does not automatically cancel a contract approval already recorded onchain.
Researchers also identified a related path that put hundreds of WETH at risk, suggesting the exposure was not limited to NFTs. The next confirmed step for affected users is to revoke the Payment Processor V2 approval before attempting to recover any rescued assets.
Source: bitcoinist.com