Magic Eden Users Face NFT Risk After Payment Processor Exploit

White-hat operation secures thousands of exposed NFTs as holders are told to revoke legacy approvals
TL;DR
- A vulnerability involving LimitBreak’s Payment Processor V2 exposed wallets that still carried old NFT approvals from Magic Eden’s discontinued EVM marketplace.
- Security researcher 0xQuit moved vulnerable NFTs into protective custody as part of a white-hat operation after attacker activity was detected.
- Users were told to revoke affected Ethereum and ApeChain contract approvals before rescued assets are returned.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
A vulnerability involving LimitBreak’s Payment Processor V2 exposed former Magic Eden EVM users to unauthorized NFT transfers because old onchain approvals remained active after the marketplace shut down, prompting a large-scale white-hat rescue on September 25, 2026. Security researcher 0xQuit, identified as Quit, VP of Blockchain at Yuga Labs, ultimately moved 23,155 NFTs worth an estimated $6 million into protective custody while affected users were told to revoke vulnerable contract permissions.
Magic Eden had ended EVM marketplace support on March 9, 2026. Its listings and offers were maintained offchain and stopped being visible or actionable after the shutdown, but approvals users had previously granted to the payment processor remained recorded onchain. Those permissions allowed the approved contract to move NFTs until wallet owners explicitly revoked them.
Wallet security service Revoke.cash warned that the Payment Processor V2 flaw placed wallets at risk if they still authorized the contract to transfer NFTs. Canceling an old marketplace listing or disconnecting a wallet from a website did not remove those blockchain approvals, making the remaining permissions the central security issue.
Early activity initially appeared to show a large-scale drain. A wallet moved 3,832 NFTs from more than 100 wallets through transactions structured as zero-ETH sales. NFT trader Cirrus drew attention to the activity before the transfers were identified as part of a defensive operation carried out by 0xQuit.
Quit later confirmed that the assets held in the rescue wallet were secure, writing: “Everything in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 is safe.” The NFTs were expected to be returned after holders removed the approvals that had left their wallets exposed.

Attacker activity triggers broader rescue
Quit said an attacker had already exploited the Payment Processor V2 weakness at about 9 a.m. EST, taking NFTs from several collections before the wider rescue operation began.
After investigating that activity, Quit determined that many more NFTs remained exposed. Payment Processor V2 could not be paused, leaving defenders unable to shut down the affected contract functionality directly.
Quit contacted LimitBreak, which was able to pause Payment Processor V3, though a V3 deployment on ApeChain temporarily could not be paused. With the vulnerable V2 contract still active, Quit said the available way to protect exposed assets was to move them into safe custody before a malicious actor could do so.
The rescue eventually expanded far beyond the first observed transfers. The earlier batch represented only the opening stage of the operation rather than the final number of assets secured.
WETH exploit path adds separate losses
Quit also determined that the processor weakness could apparently be exploited in the reverse direction to steal 660 WETH, a separate attack path from the NFT transfers. Those funds, valued at about $1.7 million, were not recovered through the NFT rescue.
The researcher said the team worked through the night attempting to contain the damage. The WETH loss remained separate from the value of the NFTs moved into white-hat custody and should not be combined with the rescued assets as though they were all stolen.
Revoke.cash initially said the final number of NFTs successfully taken by malicious actors had not been determined. Later information identified the collection-specific attacker transfers and the separate unrecovered WETH exposure, but no single finalized loss total covering the entire incident was established.
Users told to revoke legacy approvals
Revoke.cash advised Ethereum users who had authorized Payment Processor V2 to revoke that permission. ApeChain users who had approved Payment Processor V3 were separately told to revoke that authorization.
An NFT operator approval gives another contract permission to move NFTs on behalf of a wallet. Because the approval remains onchain until changed or revoked, ending a marketplace listing does not automatically remove the underlying contract permission.
That distinction meant former Magic Eden users could remain exposed even after they had stopped using the EVM marketplace. Disconnecting a wallet from the site also did not cancel permissions already recorded onchain.
Revoke.cash provided an exploit checker to help users determine whether their wallet had been affected and whether the relevant processor approval remained active. Revocation could prevent additional transfers but could not reverse assets that had already moved.
Holders whose NFTs were placed into white-hat custody were expected to remove the vulnerable approval before receiving their assets back, avoiding a return to the same exposed wallet state.
Revoke.cash had not published technical details explaining the exact underlying Payment Processor V2 flaw at the time of its warning. The established effect was that the vulnerable processor could be used to move NFTs from wallets that had previously granted it permission.
The incident did not establish malicious losses on both supported chains. The ApeChain notice concerned exposure through the V3 approval and the need for preventive revocation, while the Ethereum warning concerned the V2 contract.
The mass NFT movement also was not itself evidence that all rescued assets had been stolen. The bulk of those transfers were part of the white-hat containment effort after attacker activity showed that legacy approvals could be abused.
This article has been refined and enhanced by ChatGPT.