Skip to content

Invest1 publisher3 min readPublished

Magic Eden users must revoke a 2024 approval to reclaim 23,155 rescued NFTs

Yuga Labs researcher 0xQuit is returning 23,155 rescued NFTs to Magic Eden users, but only to wallets that revoke a 2024 Payment Processor approval. The old contract cannot be switched off, so revoking is the only protection holders have.

The Investor · Invest desk

Illustration accompanying Magic Eden users must revoke a 2024 approval to reclaim 23,155 rescued NFTs

What happened

  • Yuga Labs researcher 0xQuit opened a claim site late Saturday for NFTs rescued from the exploit of Limit Break's Payment Processor V2.
  • Whitehat researchers rescued 23,155 NFTs worth more than $5.7 million from wallets left exposed by the old approvals.
  • Owners can reclaim a rescued NFT only after revoking the 2024 Payment Processor approval that the attackers exploited.
  • Attackers have taken at least $2.8 million since September 24 from wallets on Ethereum, Polygon, Base, Arbitrum and ApeChain.
  • Assets already in the exploiters' hands cannot be recovered through the site, including 660 WETH the rescuers could not reach in time.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Limit Break cannot pause or patch V2, so no vendor fix is coming, and any wallet that keeps the 2024 approval stays drainable for as long as the contract exists.
  • exposure Holders who revoke only on the three chains Magic Eden named leave their approvals open on Arbitrum and ApeChain, where thefts were also recorded.
  • contradiction The claim site counts 26,448 recovered assets against a reported 23,155 rescued NFTs, a 3,293 gap the report does not explain, so the total owed back to owners is uncertain.

Magic Eden stopped using Limit Break's Payment Processor V2 in October 2024, but according to Revoke.cash, the approvals its users had granted were never turned off on-chain [12]. The thefts began on September 24 [2], about 23 months later [1]. The approvals stayed valid on-chain after the marketplace stopped using the contract [12]. Revoke.cash said the attack relies only on the approval, so cancelling listings does nothing to stop it [9]. That is consistent with Magic Eden's statement that no live listings were hit and that it closed its EVM marketplace in the first quarter of 2026 [19].

The attackers used the permission in two ways. They took NFTs outright, and they spent tokens held in wallets on worthless NFTs [13]. 0xQuit said the exploit could also be run in reverse to pull WETH [17]. The rescuers used the same flaw to move at-risk assets into a wallet under their control [16]. An NFT sent back to a wallet with a live approval would be open to the same exploit again, so the site releases nothing until the owner revokes [5]. The claim costs only gas [6]. "Claim site is live. If I was able to save your NFTs, you can now reclaim them," 0xQuit wrote on X [8].

The report puts the rescue at more than $5.7 million of NFTs [3] against at least $2.8 million stolen [2]. That is about two dollars saved for each dollar lost [2]. Spread over 23,155 NFTs, $5.7 million comes to roughly $246 apiece [3], and that is a floor, since the report says "more than". "660 WETH was at risk, which we unfortunately were not fast enough to recover," 0xQuit told The Block [4]. The NFTs the attackers kept will be harder to sell. OpenSea co-founder Chris Maddern said his team had flagged more than 3,000 items as stolen to block resale [21].

Owners have been slow to claim. At publication, 2,357 items had been claimed out of 26,448 recovered assets on nftsaresafu.xyz, the only official site [10]. That is about 8.9% [4], and it leaves 24,091 unclaimed in the wallet the researchers control [6]. The claim runs through a delegated wallet setup, and that can interfere with transaction simulation in some wallets [11]. Cryptopolitan has reported that fake claim sites tend to follow high-profile exploits [23].

The loss could still grow if holders who missed the news keep the approval. It could also stop growing if the attackers have already worked through the valuable wallets. Or it could turn out bigger than reported, because $2.8 million is a minimum [2]. The first theft took 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives, and more than 12 hours passed before anyone flagged it to 0xQuit [22]. I think the rest of the loss depends on how many 2024 wallets revoke, more than on anything Limit Break or Magic Eden does next. The counter-case is that the attackers took their best targets in that first window. The counter-case is right if claims stay near a tenth of the recovered assets and the stolen total stops climbing anyway.

What to watch

  • Whether owners of ERC721C and ERC1155C collections change their transfer validator settings or allowlist the claim site, cases 0xQuit said he would work through over the coming days.
  • ApeChain, where Limit Break has left Payment Processor V3 usable until November 30, 2026, after pausing it on every other chain.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls