ORBITRUM← Back to Signals

Magic Eden · security

Magic Eden Legacy EVM Approvals Expose Users in Limit Break Exploit

Magic Eden said no live listings were affected; the exploit targeted lingering approvals to Limit Break’s Payment Processor used by its former EVM marketplace.

By Orbitrum
Illustration representing Magic Eden's former EVM marketplace and vulnerable legacy smart-contract approvals, with a security shield protecting NFTs. The image highlights that white hats secured NFTs worth $5.7 million after an exploit involving old Limit Break Payment Processor permissions.

How much was protected and how much was stolen?

White hats rescued 23,155 NFTs worth more than $5.7 million, while 0xQuit initially said about 660 WETH was not recovered. Revoke.cash later put total stolen NFTs and tokens at at least $2.8 million.

Orbitrum Investor Impact

Why does the exploit matter for Magic Eden?

The incident creates trust and remediation risk because permissions granted through Magic Eden’s former EVM marketplace remained exploitable after the marketplace stopped using Payment Processor V2 in October 2024.

Are former Magic Eden users still at risk?

Yes. Payment Processor V2 cannot be paused or fixed, so wallets with active approvals remain exposed until those permissions are revoked; revoking does not recover assets already stolen.

When will the rescued NFTs be returned?

0xQuit said owners can reclaim rescued NFTs after revoking the vulnerable approvals, but no public claim date had been announced as of September 26, 2026.

What happens next?

Containment depends on users revoking remaining approvals and the rescued NFTs being returned. Revoke.cash said Payment Processor V3 was paused on other chains but remained usable on ApeChain until November 30, 2026.

Sources

Original signal: Bitcoin.com ↗

See more Orbitrum in Google

Add Orbitrum as a Preferred Source to make our research more likely to appear for you in Google Search.