In Brief:
- An attacker used a bug in Limit Break’s Payment Processor V2 to take NFTs and WETH from wallets that still had old approvals from Magic Eden’s EVM marketplace.
- Yuga Labs Vice President of Blockchain Quit said a whitehat operation moved 23,155 NFTs worth more than $5.7 million to safety, but 660 WETH wasn’t recovered in time.
- Magic Eden stopped using the contract in October 2024. It told users to revoke approvals, and it said revoking won’t return assets that have already been moved.
An attacker drained NFTs and WETH through Limit Break’s Payment Processor V2 on Sept. 25. The attack used approvals that wallets granted to the contract while trading on Magic Eden’s EVM marketplace and never revoked.
Quit, vice president of blockchain at Yuga Labs, ran a whitehat operation to move exposed assets before the attacker could reach them. “All in all, we rescued 23,155 NFTs worth north of $5.7M USD,” Quit said.
We are sharing an interim update regarding an exploit identified with @limitbreak Payment Processor V2, a NFT trading protocol maintained by the company Limit Break and which Magic Eden adopted to settle trades on EVM in 2024.
Magic Eden stopped using Payment Processor V2 in OctMagic EdenView on X ↗
Not everything was saved. Quit said a related path in the bug could be run in reverse against WETH, and 660 WETH was taken before anyone could move it.
What was taken
Quit said the first wave took 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives. Researchers then found that many more NFTs were exposed to the same attack.
The WETH drain hit harder. The first transaction alone took 281.66 WETH from 25 wallets. On ApeChain, one transaction took 7,680 WAPE from 19 wallets.
Magic Eden said the exposure is limited to old activity. NFTs listed on its EVM marketplace from about February 2024 to October 2024 could be affected. “No live Magic Eden listings were impacted,” the company said.
How the bug works
Payment Processor supports meta-transactions through trusted forwarder contracts, and anyone can deploy one. By pairing a forwarder with crafted calldata, an attacker can make the contract treat any wallet as the counterparty to a trade, without that wallet signing anything.
So canceling listings or invalidating old signatures doesn’t help. The attack needs only the wallet’s standing approval to the contract. A hardware wallet doesn’t block it either.
Pausing V3, rescuing V2
Quit said he contacted Limit Break, and the team paused Payment Processor V3, which he said carried the same bug. V2 on Ethereum couldn’t be paused. V3 on ApeChain couldn’t be paused right away either, so approved ApeChain inventory was moved as well.
“The only path towards protecting affected assets was to run a whitehat operation,” Quit said.
The rescue showed up onchain as thousands of NFTs leaving hundreds of wallets for 0 ETH. An NFT trader named Cirrus flagged the transfers early. Quit told him the receiving wallet was “a whitehat and everything in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 is safe and will be returned once they are no longer at risk.”
Rescued NFTs will go back only after owners revoke the vulnerable approval. Without that step, the tokens would be exposed again as soon as they landed. There’s no official return process yet. Owners are being warned about fake recovery pages, direct-message offers and requests to sign messages.
What to revoke
Quit listed the contract addresses. Payment Processor V2 on Ethereum is 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834, and that address also applies on Polygon and Base. Payment Processor V3 on ApeChain is 0x9a1D00000000fC540e2000560054812452eB5366. He pointed users to revoke.cash or a similar tool.
Magic Eden told anyone who listed or traded on its EVM marketplace to revoke the contract’s “approved for all” permissions on Ethereum, Polygon and Base. Token approvals for WETH, WAPE, USDC and APE should be revoked too. Disconnecting a wallet from a website leaves the onchain approvals in place.
Magic Eden said revoking can’t recover assets that have already been transferred.
Magic Eden’s role
Magic Eden described Payment Processor V2 as “a NFT trading protocol maintained by the company Limit Break and which Magic Eden adopted to settle trades on EVM in 2024.” It stopped using the contract in October 2024 and shut its EVM marketplace in the first quarter of 2026.
The company said it’s working with Limit Break, which owns and maintains the protocol, on more ways to reduce risk, including suspending transfers through the protocol. It said it’s still investigating the full scope of the damage.
Quit summed up the night in a post on X: “Worked through the entire night to save ~$6M worth of NFTs and all I’ll be able to think about is the $1.7M in WETH I wasn’t fast enough for.”