Magic Eden flags legacy EVM exposure via Limit Break V2 bug; 23,155 NFTs whitehat-rescued

security⚖️ NeutralSignal 81$WETH

⏱ 2 min read

The flaw sits in Limit Break’s payment processor, not Magic Eden’s live orderbook—highlighting how lingering approvals can outlast both listings and marketplaces.


Magic Eden warned that NFTs listed on its now-closed EVM marketplace between roughly February and October 2024 may be exposed to an exploit in Limit Break’s Payment Processor V2. The company said on X that no live Magic Eden listings were impacted and urged users who interacted with its EVM marketplace to revoke the V2 contract’s “approved for all” permissions on Ethereum, Polygon, and Base. Revoking will not return tokens that have already moved.

Scope and rescue

Yuga Labs Vice President of Blockchain 0xQuit said an attacker used the flaw to steal 10 Meebits, 50 Otherdeeds, 10 World of Women, and 235 Desperate ApeWives. He added that a whitehat operation then moved 23,155 NFTs—valued at more than $5.7 million—out of harm’s way so owners can reclaim them after revoking approvals. Roughly 660 WETH exposed to a reverse variant of the exploit could not be recovered.

Limit Break paused Payment Processor V3, which 0xQuit said had the same flaw, but V2 cannot be paused—forcing the rescue approach rather than a contract freeze.

$ETH
▼ 0.01%
$2,684

Mechanism: lingering approvals outlive listings

The risk stems from lingering permissions. Listing or trading often requires granting a settlement contract broad transfer authority; those approvals persist until explicitly revoked. That means a vulnerability in a third-party processor can impact users long after a specific listing, or even an entire marketplace line of business, has been shut down.

Why this matters

This is a protocol-layer failure in a component some marketplaces rely on to settle trades. The problem is not confined to an active orderbook: legacy approvals created a live attack surface. For users and platforms, this elevates approval hygiene from good practice to required operational control—especially where contracts are unpausable.

Limitations and open questions

The available details do not establish how many Magic Eden users remain exposed or the precise root cause of the bug. It’s also unclear how quickly owners will be able to reclaim the rescued NFTs in practice.

What to watch next

Key signals include: (1) Limit Break’s technical post-mortem and any patch or migration guidance; (2) on-chain revocation progress and the speed of NFT claims; and (3) any further thefts indicating residual exposure. Broader context: this episode follows a separate $380 million theft from Bitget, underscoring a difficult environment for crypto security.

Magic Eden previously ended support for Ethereum and Bitcoin to focus on Solana and its casino product, Dicey, later winding down its multichain wallet. The current exposure traces to approvals granted during its 2024 EVM activity.


This content is for informational purposes only and does not constitute financial advice.

🧠 HafidWatch Take

This incident reveals a structural risk in NFT trading where approvals to third-party settlement contracts can persist beyond listings and marketplace operations. The vulnerability stemmed from Limit Break’s processor rather than Magic Eden’s active orderbook, yet legacy users remained exposed. The whitehat rescue has limited direct losses, highlighting the critical importance of “approval hygiene” as an essential operational control. Key next steps include Limit Break’s technical post-mortem and the progress of revocations and NFT claims. The outcome will influence confidence levels, with any delays heightening scrutiny on protocols that act between users and marketplaces, especially those that cannot be paused.

Daily crypto intelligence. Before the market opens.

Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.

✓ Free forever  ·  ✓ No spam  ·  ✓ 50+ sources monitored

Want it faster? Join the community:

Type above and press Enter to search. Press Esc to cancel.