A vulnerability in Limit Break’s Payment Processor exposed thousands of NFTs and approved tokens across wallets that had previously interacted with NFT marketplaces including Magic Eden, triggering a large whitehat recovery operation on September 25. Researchers moved 23,155 NFTs worth more than $5.7 million into protective custody before attackers could reach them, according to Yuga Labs blockchain vice president 0xQuit. Separate malicious activity has nevertheless produced confirmed losses.
At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives.
It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the… pic.twitter.com/Vue8TUyMD2
— Quit (@0xQuit) September 25, 2026
Magic Eden said in an interim security update that the vulnerability affects Limit Break’s Payment Processor V2, which it adopted for EVM marketplace settlement in 2024 before discontinuing it that October. No current Magic Eden listing was compromised, but old on-chain approvals remained active even after the marketplace stopped using the processor. Magic Eden subsequently ended support for its EVM marketplace on March 9, 2026.
We are sharing an interim update regarding an exploit identified with @limitbreak Payment Processor V2, a NFT trading protocol maintained by the company Limit Break and which Magic Eden adopted to settle trades on EVM in 2024.
Magic Eden stopped using Payment Processor V2 in Oct…
— Magic Eden 🪄 (@MagicEden) September 25, 2026
Legacy Approvals Turn Into an Active Attack Surface
Payment Processor V2 allowed users to grant operator authority over NFT collections so trades could settle without repeatedly approving individual assets. Revoke.cash says attackers found a way to combine Payment Processor’s meta-transaction functionality with crafted calldata, making the contract treat another wallet as a trade counterparty without that owner signing the transaction. For wallets with lingering NFT approvals, the flaw could be used to execute zero-price transfers and move assets without fresh authorization.
The same general weakness could also target approved fungible tokens. Revoke.cash says attackers used worthless NFT listings to force wallets with WETH or other token approvals to complete purchases, transferring those approved assets away. As of September 25 at 12:00 UTC, the tracker estimated at least $2.8 million had been stolen across NFTs, roughly 580 WETH and other tokens, while additional attacks were still being observed.
That accounting must remain separate from the whitehat rescue. Early observers saw 3,832 NFTs moving for 0 ETH and initially interpreted the transfers as a drain, but 0xQuit subsequently identified the destination as a custody wallet. The later rescue total reached more than 23,000 NFTs, while assets successfully secured by whitehats should not be counted as stolen funds. The incident echoes the broader risk created by long-lived wallet approvals that remain usable after the original interaction has ended.
Deprecated Contracts Can Remain Dangerous
The exposure persisted because closing a marketplace interface does not revoke permissions already recorded on-chain. Payment Processor V2 has no pause or upgrade mechanism, according to Revoke.cash, leaving approved wallets vulnerable unless owners explicitly remove the authorization. A deprecated front end and an inactive listing do not deactivate an ERC-721 operator approval. That residual-risk problem resembles other cases where legacy smart contracts remained economically dangerous long after their original deployment.
Payment Processor V3 on ApeChain was also identified as containing the same flaw, while Limit Break moved to pause affected V3 deployments. Users previously granting Payment Processor V2 or V3 authority remain exposed until the relevant NFT and token approvals are revoked on-chain. Canceling an old listing, disconnecting a wallet from a website or invalidating a marketplace order does not independently remove the underlying operator permission.
The incident illustrates why the security boundary should remain precise. Neither Ethereum nor Magic Eden’s current marketplace infrastructure was itself compromised; the exploitable component was Limit Break’s Payment Processor combined with persistent user approvals. Similar distinctions matter when analyzing application-level failures separately from the blockchain infrastructure beneath them.
The next concrete milestone is reconciliation and restitution. Owners of rescued NFTs must revoke the vulnerable approvals before assets can safely be returned, while Limit Break and security researchers still need to publish a complete root-cause analysis and final accounting of malicious losses. Until then, the $5.7 million rescue and the estimated $2.8 million stolen represent different sides of an incident that remains under active investigation.
