Live Prices
NFTs

Magic Eden NFT Approvals Expose Wallets After 3,832 NFTs Moved in Whitehat Rescue

TheCryptoDesk Editorial · 2m read
Magic Eden NFT Approvals Expose Wallets After 3,832 NFTs Moved in Whitehat Rescue

Security monitoring platform Revoke.cash issued a warning on Sept. 25 regarding a critical security vulnerability in Limit Break's Payment Processor V2, which prompted whitehat researcher 0xQuit to move 3,832 NFTs out of vulnerable wallets using zero-ETH transactions.\n\n## Legacy Onchain Approvals Create Security Vulnerability\n\nAlthough Magic Eden officially discontinued EVM marketplace support on March 9, 2026, offchain listings and offers were simply removed from the platform's interface while underlying smart contract approvals remained active onchain. Because wallet disconnects and listing cancellations do not erase smart contract permissions, users who authorized Limit Break's Payment Processor V2 remained exposed. Exploiting this oversight, security researcher 0xQuit initiated zero-ETH sales to transfer 3,832 NFTs into a secure custody wallet until they can be safely returned to their owners, building on previous security events where Magic Eden NFTs were secured in whitehat custody.\n\n## Revoke.cash Urges Immediate Permission Revocation\n\nIn response to the flaw, Revoke.cash released an exploit checker enabling users to review their wallet addresses for active permissions. The security firm advises former marketplace users to immediately revoke operator approvals for Payment Processor V2 on Ethereum as well as Payment Processor V3 on ApeChain. Although technical details of the vulnerability remain unpublished and it is unknown whether malicious actors stole assets before the rescue, revoking approvals serves as an essential preventive measure.\n\nKey Takeaways:\n- Whitehat researcher 0xQuit rescued 3,832 NFTs via zero-ETH sales using a flaw in Limit Break's Payment Processor V2.\n- Magic Eden ended EVM marketplace support on March 9, 2026, but active smart contract approvals remained onchain.\n- Revoke.cash urges users to revoke permissions for Payment Processor V2 on Ethereum and Payment Processor V3 on ApeChain.\n\n## Why It Matters\n\nThis incident highlights a persistent risk in decentralized finance and NFT ecosystems: smart contract approvals endure indefinitely onchain regardless of frontend marketplace shutdowns. As web3 platforms sunset services or update infrastructure, lingering permissions create silent attack vectors for newly discovered vulnerabilities. NFT collectors must prioritize regular wallet hygiene and actively revoke unused contract approvals rather than assuming inactive marketplaces present no risk.

Terms in this article

Read next