Skip to content

Invest2 publishers3 min readPublished

Two-year-old Magic Eden listing approvals handed an attacker 305 NFTs

Approvals Magic Eden users granted in 2024 let an attacker take 305 NFTs through Limit Break's Payment Processor V2 this September. Closing the marketplace left those permissions working, so NFT holders should revoke on a schedule.

The Investor · Invest desk

Illustration accompanying Two-year-old Magic Eden listing approvals handed an attacker 305 NFTs

What happened

  • Yuga Labs' 0xQuit said a whitehat operation rescued 23,155 NFTs worth more than $5.7 million before the attacker could reach them.
  • 660 wrapped ether exposed to a reverse version of the exploit was not recovered in time.
  • Magic Eden told users to revoke the contract's "approved for all" permissions on Ethereum, Polygon and Base using Revoke.cash.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Holders pay for whatever the rescue missed, since revoking returns nothing already moved and neither report names anyone covering the losses.
  • constraint With no pause switch on V2, protection for every 2024 lister depends on that wallet revoking on three chains, and a missed warning leaves it open.
  • decision Rescued owners have to revoke before they can reclaim, so getting a token back forces the step that was skipped for roughly two years.
  • contradiction Cointelegraph's early count of 3,832 NFTs moved was about a sixth of 0xQuit's later 23,155, so first reports understated the exposure.

A holder who listed an NFT on Magic Eden's Ethereum-compatible marketplace in October 2024 signed a permission the marketplace stopped using that same month [2]. The permission stayed live, because a listing approval lasts until the owner revokes it [4]. Somewhere between 23 and 31 months after those approvals were signed, at 9AM EST on September 25, 2026, somebody abused a bug in Payment Processor V2, according to Yuga Labs' 0xQuit [1][7][4]. Magic Eden had already shut the whole EVM marketplace in early 2026 [2]. Shutting the storefront did not touch the contract or the approvals pointed at it [4].

"No live Magic Eden listings were impacted in this exploit," the company said on X [3]. The statement is accurate. The exposed listings dated from roughly February to October 2024 [1], and the marketplace stopped routing trades through the contract that October [2].

Limit Break paused Payment Processor V3, which carried the same flaw, but V2 could not be paused [8]. That left two protections on V2. One is each holder revoking the contract's "approved for all" permission on Ethereum, Polygon and Base [5]. The other is a whitehat rescue, and a rescue depends on someone noticing. "It wasn't until over 12 hours later that somebody reported it to me," 0xQuit wrote [7].

Once it began, the rescue was large. "All in all, we rescued 23,155 NFTs worth north of $5.7M USD," 0xQuit wrote [9]. The attacker took 305 NFTs (10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives) [6][1]. So the whitehats saved about 76 tokens for every one lost [3], worth at least $246 each on average [2]. The loss that was not recovered was fungible: 660 WETH exposed to a reverse version of the exploit was not recovered in time [11].

Magic Eden's attention is elsewhere. It dropped Ethereum and Bitcoin support in February to focus on Solana and its crypto casino, Dicey, then wound down its multichain wallet [12]. Its response to a flaw in a contract it adopted in 2024 [2] is a warning and a link to Revoke.cash [5]. Cointelegraph had no reply from the company by publication [16].

The case can still go two ways. If owners revoke and reclaim (0xQuit said the tokens "will be returned once they are no longer at risk") [14][10], the tally stays at 305 NFTs and 660 WETH [1][11]. If some 2024 wallets never see the warning, V2 stays open to them with nobody able to switch it off [8].

I think revocation has to be routine for anyone holding NFTs: done whenever a venue stops using a contract, and repeated on a schedule. These approvals outlived both the contract's use and the marketplace itself [2][4]. The counter-thesis is that the backstop worked. The ratio was 76 saved per token lost [3], and 0xQuit ran a similar recovery in June, getting back 68 NFTs worth more than $500,000 after an exploit at Flooring Protocol [15]. But the backstop was one Yuga Labs executive's operation, and it started more than 12 hours after the theft began [7]. The view is wrong if the rescued tokens are returned intact and no further drain through a dormant 2024 approval appears. In that case the argument rests on one contract that happened to lack a pause switch [8].

What to watch

  • Whether owners revoke and reclaim the 23,155 rescued NFTs, and how many remain unclaimed in the rescue wallet.
  • Any new drain through Payment Processor V2 from 2024 wallets that have not revoked on Ethereum, Polygon or Base.
  • The further details on the vulnerability that Yuga Labs CEO Michael Figge said the company would share.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories