Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit
What happened
Revoking won't return tokens that have already moved. Magic Eden adopted the contract to settle trades in 2024, stopped using it that October and shut its EVM marketplace entirely in early 2026.
A flaw in Limit Break's Payment Processor V2 put old Magic Eden Ethereum listings at risk, prompting a whitehat rescue of more than 23,000 NFTs. Yuga Labs' 0xQuit said a whitehat operation rescued 23,155 NFTs worth more than $5.7 million, but 660 WETH couldn't be recovered.
Users should revoke the contract's approvals on Ethereum, Polygon and Base. EVM refers to Ethereum and the blockchains compatible with it.
"No live Magic Eden listings were impacted in this exploit," the company said on X. When users list NFTs, they typically grant a contract permission to move them, and that permission stays active until it's revoked.
Magic Eden urged anyone who listed or traded on its EVM marketplace to revoke the V2 contract's "approved for all" permissions on Ethereum, Polygon, and Base using Revoke.cash. At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives.
Sources & evidence
- Decrypt Reporting source
Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit ↗
https://decrypt.co/379342/magic-eden-old-ethereum-nft-listings-exposed-exploit