TL;DR
- Magic Eden says old EVM marketplace approvals left more than $5.7 million worth of NFTs exposed to an exploit in Limit Break’s Payment Processor V2.
- A whitehat rescue operation moved 23,155 vulnerable NFTs before they could be stolen.
- Magic Eden says no live listings were affected, but users who interacted with the old marketplace should revoke lingering approvals.
An old smart contract can remain dangerous long after the product built around it has disappeared.
Magic Eden is grappling with just that issue after legacy approvals from its defunct EVM marketplace left thousands of NFTs exposed to a vulnerability in Limit Break’s Payment Processor V2.
The marketplace reported that over $5.7 million worth of NFTs were at risk of theft.
The Marketplace Was Closed, But The Approvals Were Still Live
Magic Eden ceased using Payment Processor V2 in October 2024 and subsequently shut down its EVM marketplace.
However, this closure did not revoke permissions that users had previously granted to the contract.
When an attacker exploited the processor this week, those old approvals became relevant again.
The initial theft comprised assets from well-known collections such as Meebits, Otherdeeds, and World of Women.
Security researchers quickly recognized that a far larger number of wallets remained vulnerable.
A whitehat rescue operation ultimately secured 23,155 NFTs worth more than $5.7 million before they could be stolen.
Users can expect to reclaim rescued assets after revoking the vulnerable approval.
Magic Eden assured that no active listings on its current products were affected by this incident.
Token Approvals Can Outlive The App That Asked For Them
This incident serves as a critical reminder of how wallet permissions function.
When a user grants a marketplace or protocol permission to transfer assets, that authorization can remain valid until it is explicitly revoked.
Closing a website does not necessarily terminate the existing permissions.
Switching marketplaces does not automatically remove old approvals.
Even abandoning a wallet interface does not alter what has been approved on-chain.
Magic Eden advises users who interacted with its EVM marketplace during the affected timeframe to revoke Payment Processor V2 permissions across supported networks including Ethereum, Polygon, and Base.
Researchers also identified a related vulnerability that endangered hundreds of WETH, indicating that the exploit was not confined to NFTs.
The technical issue resides within Limit Break’s processor rather than Magic Eden’s live marketplace.
Nevertheless, old Magic Eden approvals significantly widened the pool of users potentially exposed to the risk.
In the realm of crypto security, the focus often centers on what permissions are being signed today.
This incident highlights the importance of previously granted permissions that can still pose a threat.
This article was written by the News Desk and edited by Samuel Rae.
