top of page

Magic Eden NFT Exploit Puts 3,832 NFTs at Risk

1 hour ago
5 min read


Magic Eden

A Whitehat Rescue Worth Millions

The NFT market got another reminder that old blockchain approvals can become a serious security risk long after a platform stops using a particular protocol.

On September 25, a whitehat operator rescued 3,832 NFTs from hundreds of wallets after an exploit was discovered in Limit Break’s Payment Processor V2. The protocol was previously used by Magic Eden to settle Ethereum trades through its EVM marketplace in 2024.

The rescued NFTs include assets from major collections such as Bored Ape Yacht Club, Mutant Ape Yacht Club, Azuki, Otherdeed, Doodles, Moonbirds, CloneX, DeGods and Captainz. An unverified estimate places the combined value of the haul at around $1.4 million, although that figure has not been independently confirmed.

The important detail? These NFTs were not simply stolen and disappeared. A whitehat operator moved them to a secure address to prevent the exploit from taking them.

For anyone following blockchain games, the incident is particularly relevant because NFTs often represent in-game items, characters, land and other digital assets that can remain valuable for years.


What Happened to the 3,832 NFTs?

The activity began early on September 25.

At approximately 06:31 UTC, NFT tracker CirrusNFT flagged thousands of NFTs moving from hundreds of different wallets. Just four minutes later, the transfers appeared as sales connected to Magic Eden's former marketplace.

There was an immediate reason for concern: the transfers were executed for 0 ETH.

A normal NFT sale would involve a payment, so the unusual transaction pattern quickly suggested that something else was happening.

By around 06:42 UTC, trackers suspected the activity could be a whitehat rescue rather than a conventional theft. Five minutes later, Yuga Labs vice president of blockchain 0xQuit publicly confirmed that the NFTs had been moved as part of a rescue operation.

The assets were consolidated into a single address and are expected to be returned once the security risk has been addressed.


Magic Eden Says Its Live Listings Were Not Affected

Magic Eden has emphasized that the vulnerability was in Limit Break's Payment Processor V2, rather than in Magic Eden's own systems.

The marketplace previously used Payment Processor V2 for EVM transactions but stopped using it in October 2024. Magic Eden subsequently shut down its EVM marketplace entirely during the first quarter of 2026.

According to Magic Eden, no live listings were affected by the exploit.

However, there is an important historical exposure window.

NFTs that were listed on Magic Eden's EVM marketplace between approximately February 2024 and October 2024 could potentially still have approvals connected to Payment Processor V2.

Listings created after October 2024 should not be affected by this particular issue.

Magic Eden is also working with Limit Break to investigate additional mitigation options, including whether transfers through the vulnerable protocol can be paused.


The Problem Was Old NFT Approvals

This incident highlights one of the less obvious risks of using NFT marketplaces: approvals can outlive the platforms that requested them.

When someone lists an NFT, they generally need to approve a smart contract to move that NFT from their wallet when a sale takes place.

The problem is that these permissions don't automatically disappear when:

  • A listing is canceled

  • A marketplace changes its infrastructure

  • A protocol is no longer being used

  • A marketplace eventually shuts down

In the Payment Processor V2 case, users who interacted with the protocol in 2024 could still have active approvals in their wallets.

That created a potential path for NFTs to be moved without the owners signing a new transaction.

This is an important distinction: the vulnerability wasn't necessarily about users giving a new approval on September 25. It involved permissions that had remained active from earlier interactions.


Which NFT Collections Were Rescued?

The whitehat operation affected a surprisingly broad collection of recognizable Ethereum NFTs.

Among the collections represented in the rescued assets were:

  • Bored Ape Yacht Club

  • Mutant Ape Yacht Club

  • Azuki

  • Doodles

  • Moonbirds

  • CloneX

  • DeGods

  • Meebits

  • Otherdeed

  • Art Blocks

  • Nakamigos

  • Opepen

  • Quirkling

  • Captainz

The estimated $1.4 million valuation should be treated cautiously because it has not been verified. NFT values can also fluctuate considerably depending on the individual token, rarity and market conditions.

Still, the number of affected assets shows how significant a dormant smart-contract approval can become when a widely used protocol is compromised.


How Users Can Revoke Payment Processor V2

Magic Eden has advised users who may have interacted with the old EVM marketplace to review and revoke their approvals.

The contract identified in its guidance is:

Limit Break: Payment Processor (V2)

Users can check their approvals through Revoke.cash and review the Ethereum permissions associated with the contract. Magic Eden's instructions also call for the process to be repeated on Polygon and Base.

The general process involves:

  1. Connecting the relevant wallet to Revoke.cash.

  2. Selecting Ethereum.

  3. Searching for the Payment Processor V2 contract.

  4. Reviewing NFT approvals marked "approved for all."

  5. Revoking the relevant permissions.

  6. Repeating the process on Polygon and Base.

0xQuit has also highlighted Payment Processor V3 on ApeChain in separate guidance, so users who interacted with that ecosystem should review their approvals as well.

One warning is particularly important: revoking an approval does not recover an NFT that has already been transferred.

Revocation protects assets that remain in the wallet by removing the contract's ability to move them in the future.


A Familiar Whitehat Steps In

The rescue was carried out by 0xQuit, a blockchain security researcher and Yuga Labs vice president of blockchain.

He publicly confirmed that the NFTs moved into the rescue address were safe and would be returned once the assets were no longer at risk. Magic Eden subsequently thanked him for helping protect affected users and bringing attention to the vulnerability.

This isn't the first time 0xQuit has performed this type of intervention.

In June, he reportedly helped recover 68 NFTs worth more than $500,000 following an exploit involving Flooring Protocol.

Whitehat operations like this can look alarming at first because NFTs suddenly disappear from their owners' wallets. The difference is the intent: the assets are moved into a controlled address to prevent an attacker from taking them, rather than being transferred for personal gain.


What This Means for NFT and Blockchain Gaming Users

For gamers and collectors, the Magic Eden incident offers a useful security lesson.

NFT-based games can involve numerous smart-contract interactions, including approvals for marketplaces, trading systems, staking platforms and other applications. Players may approve contracts once and then forget about them for months or even years.

That makes regularly reviewing wallet permissions an important part of digital-asset security.

The incident also demonstrates why shutting down a marketplace doesn't necessarily eliminate every technical connection created during its operation. The front end can disappear while an on-chain approval remains active.

Magic Eden has said the rescued NFTs are currently sitting in the whitehat address and will be returned once the risk has passed. The company is continuing to investigate the incident alongside Limit Break.

For NFT holders, the immediate takeaway is straightforward: old approvals deserve attention, especially when they belong to contracts that are no longer actively used.

Comments


Published: September 25, 2026 at 17:30 UTC

bottom of page