A vulnerability involving Limit Break’s Payment Processor V2 exposed more than $5.7 million worth of NFTs associated with legacy Magic Eden approvals, even though Magic Eden had stopped using the processor in 2024 and later shut down its EVM marketplace. The Block
Magic Eden said no live listings were affected. The exposure instead came from approvals that users had previously granted and left active on-chain. NFTs listed through the EVM marketplace between roughly February and October 2024 may have been affected. The Block
The initial attacker stole NFTs including Meebits, Otherdeeds, World of Women assets and Desperate ApeWives. Limit Break paused Payment Processor V3, which reportedly contained the same bug, but V2 could not be paused. The Block
A white-hat operation subsequently rescued 23,155 NFTs valued at more than $5.7 million. A related route also placed 660 WETH at risk, which the rescuers were unable to secure in time. The Block
Magic Eden advised affected users to revoke Payment Processor V2 approvals on Ethereum, Polygon and Base before reclaiming rescued NFTs.
TOKEN RECON ASSESSMENT
This incident illustrates a persistent smart-contract hazard: closing an application does not automatically terminate permissions users granted to its contracts.
The security perimeter therefore extends beyond currently active protocols. Dormant approvals can remain exploitable long after users believe they have stopped interacting with a platform.
The broader confirmation signal will be whether major wallets and marketplaces begin making stale-approval monitoring and revocation a more prominent security feature.
Source
The Block: Magic Eden legacy approvals exposed $5.7 million in NFTs