ORBITRUM← Back to Signals

Magic Eden · security

Magic Eden Legacy Approvals Expose Former EVM Users to Limit Break Exploit

No current Magic Eden listings were reported affected; the exploit targets lingering Payment Processor approvals from its former EVM marketplace, and wallets that have not revoked those permissions can remain exposed.

By Orbitrum
Illustration of Magic Eden and an Ethereum wallet approval interface highlighting a legacy smart-contract security exposure. A whitehat operation moved 23,155 NFTs valued at more than $5.7 million to safety after a flaw in Limit Break’s Payment Processor V2 exposed old marketplace approvals; 660 WETH was not recovered.

Are current Magic Eden listings affected?

No. Magic Eden said the affected approvals mainly came from EVM listings made between roughly February and October 2024, before it stopped using Payment Processor V2.

Orbitrum Investor Impact

How much was rescued or stolen?

0xQuit said whitehats rescued 23,155 NFTs worth more than $5.7 million. Revoke.cash later tracked at least $2.8 million of NFTs and tokens stolen across affected networks.

Why does the exploit matter for Magic Eden?

It is primarily a legacy security and customer-remediation issue rather than a disruption to current listings. Magic Eden stopped using Payment Processor V2 in October 2024 and closed its EVM marketplace in the first quarter of 2026.

Can former Magic Eden users still be at risk?

Yes. Payment Processor V2 cannot be paused or fixed, so previously granted approvals remain exploitable until users revoke them.

What happens next for affected users?

Users need to revoke Payment Processor approvals, and a claim portal is available for rescued NFTs after revocation. Magic Eden said it is continuing to assess the incident and work with Limit Break on mitigation.

Sources

Original signal: TokenPost ↗

See more Orbitrum in Google

Add Orbitrum as a Preferred Source to make our research more likely to appear for you in Google Search.