A vulnerability in a two-year-old settlement contract forced an overnight whitehat rescue of more than 23,000 NFTs this week, after an attacker demonstrated that permissions granted on Magic Eden's long-closed Ethereum marketplace never actually expired.

The flaw sat in Limit Break's Payment Processor V2, which Magic Eden used to settle trades on its EVM marketplace between roughly February and October 2024. Magic Eden stopped using the processor in October 2024 and shut the marketplace entirely in March 2026 — but the operator approvals users had granted the contract lived on, onchain, waiting for anyone with the right exploit.

The Timeline

The attack began Thursday, September 24 at 13:08 UTC, when a single address pulled 305 NFTs — including 10 Meebits, 50 Otherdeeds, 10 World of Women tokens and 235 Desperate ApeWives — out of one wallet in three transactions priced at zero, according to BigGo Finance's reconstruction. Nobody noticed for twelve hours.

Yuga Labs Vice President of Blockchain 0xQuit, who first identified the breach, realized the same bug could reach a far larger pool of wallets and contacted Limit Break. The company paused Payment Processor V3 on ApeChain — but V2 on Ethereum could not be halted. That left one option: use the vulnerability itself to move exposed assets to safety before attackers could. Starting Friday at 05:46 UTC, 0xQuit and helpers pulled 23,155 NFTs worth more than $5.7 million into a custody address. "All in all, we rescued 23,155 NFTs worth north of $5.7M USD," 0xQuit wrote.

What Was Lost

Not everything was secured in time. About 660 WETH exposed through a reverse variant of the exploit was drained before the rescue closed the window. On-chain counts attributed by BigGo put confirmed losses at 530.7 WETH from 911 Ethereum wallets (roughly $1.43 million), 8,380 USDC from 62 wallets, about 549,000 WILD tokens, and 7,680 wrapped ApeCoin taken on ApeChain in a single transaction.

Magic Eden said no live listings were impacted. "No live Magic Eden listings were impacted in this exploit," the company posted on X, urging former users to revoke old approvals. CryptoSlate, citing a September 25 Revoke.cash warning, notes the service could not establish how many NFTs malicious actors ultimately took beyond the initial theft.

Recovery and Remediation

A public recovery portal, nftsaresafu.xyz, is now live for owners of rescued NFTs to reclaim their assets after revoking the affected approvals, as CryptoRank reports. 0xQuit has run this playbook before: in June he helped recover 68 NFTs worth more than $500,000 after the Flooring Protocol exploit, holding them until the underlying issue was resolved.

Users who traded on Magic Eden's EVM marketplace should revoke "approved for all" permissions for Payment Processor V2 at 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 on Ethereum, Polygon and Base, and for Payment Processor V3 at 0x9a1D00000000fC540e2000560054812452eB5366 on ApeChain. Revoke.cash hosts a dedicated checker for the incident.

The Lesson

The uncomfortable detail is that a hardware wallet offers no protection here — the user already signed the approval, and the permission lives in the token contract, not on the device. Canceling an old listing doesn't help either; the approval is a separate onchain fact. Marketplaces come and go, but approvals are forever until revoked. This incident is the clearest demonstration yet that decommissioned infrastructure is not gone infrastructure.

TrustGrade tracks the security posture of platforms and firms in digital assets. Verified trust data: trustgrade.ai.