
AI-generated summary
Magic Eden operated an EVM-compatible marketplace using Limit Break's Payment Processor V2 protocol from February 2024 until October 2024, when it discontinued the service and fully shut down the EVM marketplace in early 2026.
Magic Eden may have left Ethereum behind, but some of its old users' NFTs were still exposed.
The marketplace warned Friday that NFTs listed on its EVM marketplace between roughly February and October 2024 could be affected by an exploit in Payment Processor V2, an NFT trading protocol built and maintained by Limit Break.
EVM refers to Ethereum and the blockchains compatible with it. Magic Eden adopted the contract to settle trades in 2024, stopped using it that October and shut its EVM marketplace entirely in early 2026.
"No live Magic Eden listings were impacted in this exploit," the company said on X.
The problem lies in lingering approvals. When users list NFTs, they typically grant a contract permission to move them, and that permission stays active until it's revoked.
Magic Eden urged anyone who listed or traded on its EVM marketplace to revoke the V2 contract's "approved for all" permissions on Ethereum, Polygon, and Base using Revoke.cash. It noted that revoking won't return tokens that have already moved.
Yuga Labs Vice President of Blockchain 0xQuit said an attacker used the bug to take 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. Limit Break paused Payment Processor V3, which had the same flaw, but V2 couldn't be paused. That forced a whitehat rescue, an operation in which friendly hackers move vulnerable assets to safety before attackers can.
"All in all, we rescued 23,155 NFTs worth north of $5.7M USD," 0xQuit wrote. Owners will be able to reclaim them after revoking the approvals, according to 0xQuit.
But 660 wrapped Ethereum, or WETH, exposed to a reverse version of the exploit wasn't recovered in time.
Magic Eden dropped Ethereum and Bitcoin support in February to focus on Solana and its crypto casino, Dicey. It later wound down its multichain wallet.
AI outlook — possibilities, not facts
Users who revoke approvals will be able to reclaim rescued NFTs
Very likely · Within weeks

Security firm SlowMist reports no confirmed cryptocurrency thefts linked to a recent Safari exploit targeting iPhones. While the exploit can access Keychain data, the firm clarifies that the widely reported iOS 13-26.5 range is preliminary and unverified.

MultiversX brought its blockchain mainnet back online Thursday, Sept. 24, about five days after an exploit-related halt. While block production has resumed, crypto exchanges like Kraken maintain trading and funding restrictions.

A whitehat moved 3,832 NFTs from hundreds of wallets amid vulnerability concerns regarding NFT marketplace Magic Eden. Yuga Labs executives confirmed the rescue operation, while Magic Eden has not publicly confirmed an exploit.

Researchers at [[alloc] init] published a 56-page paper detailing Shielded Bitcoin, a protocol enabling private transfers on Bitcoin's base layer using zero-knowledge proofs and encrypted notes.

Payy has frozen its stablecoin payment network and card transactions after its Ethereum bridge contract was exploited and drained on Sept. 24.

Australian Prime Minister Anthony Albanese warned at the UN General Assembly that AI is advancing too quickly without safeguards, citing an OpenAI agent's breach of an Australian government Medicare statistics portal in June, which was not reported to authorities until September.