Magic Eden unfairly targeted. Thousands of NFTs have left their wallets via an old contract previously integrated into its EVM marketplace. However, the flaw actually originated from Limit Break's Payment Processor V2, which an attacker had already begun exploiting when 0xQuit, VP of Blockchain at Yuga Labs, launched a rescue operation.
The white hat secured 23,155 NFTs valued at over $5.7 million. Conversely, about 660 WETH, or nearly $1.7 million, could not be recovered at this stage. Here is what we know.
Key takeaways
- The vulnerability concerned Limit Break's Payment Processor V2, which was previously integrated by Magic Eden
- 0xQuit secured 23,155 NFTs estimated at over $5.7 million
- An attacker had already begun exploiting the flaw, and approximately 660 WETH were not recovered
- Affected holders must revoke their allowances on Ethereum V2 and ApeChain V3 contracts
Magic Eden under fire, an old vulnerability at Limit Break
The first movements immediately drew attention. Thousands of NFTs were leaving hundreds of wallets via transactions displayed as 0 ETH sales, all heading toward the same address. Because block explorers associated these operations with Magic Eden, the marketplace found itself at the center of suspicion.
However, the vulnerability resided in Limit Break's Payment Processor V2, a protocol for NFT sales formerly integrated by Magic Eden to enforce creator royalties. The platform had stopped using this version in October 2024, before shutting down its EVM market on March 9, 2026. While listings, offers, and auctions disappeared from its interface, the permissions granted directly on the blockchains remained active.
An attacker had already exploited the flaw when the Yuga Labs team identified the issue. The first stolen assets included Meebits, Otherdeeds, World of Women, and Desperate ApeWives.
0xQuit and Limit Break then launched a rescue operation. Initial observations reported 3,832 NFTs moved, but the final count reached 23,155 NFTs, valued at over $5.7 million. They have been gathered into a single address, and 0xQuit confirms that they are safe and can be returned once the vulnerable permissions are revoked.

Limit Break: Old approvals exposed NFTs and WETH
To function, the Payment Processor required authorization to move NFTs listed for sale. Yet, an approval granted to a smart contract generally remains active until revoked, even when the service using it closes down or changes protocols.
This flaw allowed an attacker to pose as the owner of an NFT still covered by this authorization, then trigger its transfer for 0 ETH. No active listing on Magic Eden was necessary: the approval left in the wallet was enough to maintain exposure.
The team also discovered that an inverse variant could target WETH, the tokenized ether often used to place bids on NFTs. Approximately 660 WETH were exposed and could not be recovered during the rescue operation. 0xQuit estimates the loss at nearly $1.7 million, though future recovery cannot be ruled out entirely.
The Payment Processor V3 deployed on ApeChain had a similar weakness. Limit Break was able to suspend this version, unlike the Ethereum V2 contract, which remained accessible due to its decentralized nature.
0xQuit recommends revoking permissions granted to the following two addresses:
- Ethereum V2: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834
- ApeChain V3: 0x9a1D00000000fC540e2000560054812452eB5366
This can be done using a tool like revoke.cash. While this does not automatically retrieve assets already moved, it prevents the affected contract from transferring any new ones.
The incident did not stem from a fresh compromise of Magic Eden. Rather, it illustrates how an authorization granted to an old contract can persist years after its intended use, continuing to expose assets held in a wallet. This is indeed self-custody, but it isn't always easy to keep track of.
The news that matters, summarized in 2 minutes. Monday to Friday, in your inbox.