In Brief:
- OpenSea has marked more than 3,000 items as stolen and blocked them from trading after an exploit of Limit Break‘s Payment Processor V2 contract, which Magic Eden once used to settle EVM trades.
- Attackers used old approvals that were never switched off to take NFTs and tokens worth at least $2.8 million, according to Revoke.cash.
- A whitehat team led by Yuga Labs’ 0xQuit rescued 23,155 NFTs worth more than $5.7 million, and a claim site is now live.
OpenSea has flagged more than 3,000 NFTs as stolen and blocked them from trading after a security incident involving Magic Eden and Limit Break, Chris Maddern of OpenSea said.
“we’re aware of a security incident affecting Magic Eden & Limit Break,” Maddern said. “the team is working to make sure that these items are not able to be re-sold on @opensea.” He said “so far over 3,000 items have been marked as stolen & prevented trading.”
a short update on the limit break / magic eden incident response
as a reminder, no @opensea systems or contracts are affected
> known-impacted ERC721 NFTs have been flagged on OpenSea & cannot be sold
> newly exploited NFTs are automatically flagged (limiting exploiter accessChris MaddernView on X ↗
In a follow-up, Maddern said “no @opensea systems or contracts are affected.” He said “known-impacted ERC721 NFTs have been flagged on OpenSea & cannot be sold” and that “newly exploited NFTs are automatically flagged.”
Old approvals, new exploit
The flaw sits in Payment Processor V2, a contract Limit Break maintains. Magic Eden used it to settle trades on EVM networks from February to October 2024, then stopped. It shut its EVM marketplace entirely in the first quarter of 2026.
The approvals users granted the contract during that window stayed active on-chain. Starting around 9 a.m. EST on Sept. 24, attackers abused a bug that let them act on behalf of any wallet that had approved the protocol.
They took NFTs for free. They also drained approved tokens by forcing wallets to buy worthless NFTs. One address pulled 305 NFTs from a single wallet in three transactions, each recorded as a “sale” at a price of zero.
The first reported theft included 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives, according to 0xQuit, Yuga Labs vice president of blockchain.
Revoke.cash said attackers have taken NFTs and tokens worth at least $2.8 million across Ethereum, Polygon, Base, Arbitrum and ApeChain. It said thefts were still ongoing. Revoke.cash has an exploit checker live for users to test their addresses.
Whitehat rescue
V2 can’t be paused or fixed, so it remains vulnerable. Limit Break paused Payment Processor V3, which carried the same flaw, on every chain except ApeChain. There, V3 stays usable until Nov. 30, 2026.
With V2 still open, a group of security researchers used the same bug to move exposed NFTs into a wallet they control. Coffeedev, 0xjustadev and whiteoakkong joined 0xQuit in the operation.
“All in all, we rescued 23,155 NFTs worth north of $5.7M USD,” 0xQuit said.
Not everything was saved. “660 WETH was at risk, which we unfortunately were not fast enough to recover,” 0xQuit said. The exploit could be run in reverse to pull WETH, he said.
An earlier count had put the rescue at 3,832 NFTs, a figure that likely reflected a tally taken partway through the operation.
Claims and revocations
A claim site at nftsaresafu.xyz is the only official one. As of the latest count, 2,357 of the 26,448 recovered assets had been claimed.
Owners must revoke their Payment Processor approval before they can claim. 0xQuit warned that holders of ERC721C or ERC1155C collections may not be able to claim because of transfer validator rules.
The contracts to revoke are 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 on Ethereum, Polygon and Base, and 0x9a1D00000000fC540e2000560054812452eB5366 on ApeChain. Arbitrum should be checked too. The permissions cover “approved for all” NFT approvals as well as token approvals for WETH, WAPE, USDC or APE. Wallets usually label the contract “Limit Break: Payment Processor.”
Cancelling listings doesn’t help. The attack relies only on the approval, Revoke.cash said.
Magic Eden warned that NFTs listed on its EVM marketplace before October 2024 could be affected, while newer listings are safe. Co-founder and CEO Jack Lu said the incident concerns Limit Break’s trading protocol and contracts, which Magic Eden stopped using two years ago.
Revoking protects what’s still in a wallet. It doesn’t bring back what’s already gone.
