An old NFT marketplace contract is being actively exploited, and this one is a good reminder that “I stopped using that platform years ago” doesn’t necessarily mean you’re safe.
The vulnerability is in Limit Break’s Payment Processor V2, which Magic Eden used for its EVM marketplace in 2024.
Magic Eden itself was not hacked. The problem is that users who interacted with the old marketplace may still have active token or NFT approvals to the vulnerable contract.
Attackers can exploit those approvals to:
• Take NFTs without the owner signing a transaction
• Drain WETH, USDC and other approved tokens
• Bypass canceled listings and invalidated signatures
The attacks are already happening across multiple EVM chains, with millions in assets reportedly stolen.
Whitehats are also racing to rescue NFTs before attackers can take them. Thousands have reportedly been moved to a custody wallet for eventual return to owners who revoke their approvals.
The scary part?
The vulnerable contract can’t simply be paused or upgraded.
If you ever used Magic Eden’s EVM marketplace, especially in 2024, go check your wallet approvals.
Revoke.cash has a dedicated checker for this exploit. Revoke the old approvals now if you have them.
And remember: revoking an approval prevents future theft. It does not recover anything that has already been stolen.
This is a pretty stark example of why wallet hygiene matters even after you’ve completely moved on from a protocol.
Sep 25, 2026 · 2:29 PM UTC
6
1
17
1,213







