The September 2026 alarm began with thousands of NFTs leaving wallets in transactions that looked like zero-price Magic Eden sales. The underlying flaw was in Limit Break’s Payment Processor, a protocol Magic Eden had previously used—not in Magic Eden’s live listings. Old onchain approvals remained usable after the marketplace stopped using the contract.
19
22
From theft to a public alarm
Revoke.cash dates the start of exploitation to September 24, 2026. The flaw allowed someone to act on behalf of wallets that had approved the Payment Processor: attackers could take approved NFTs for free or drain approved tokens by making a wallet buy a worthless NFT.
39
According to Yuga Labs blockchain vice president Quit, also known as 0xQuit, an attacker stole 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives. Those reported thefts should not be confused with the much larger set of transfers spotted the following day.
9
27
On September 25, NFT trader Cirrus flagged a wallet moving 3,832 NFTs from hundreds of wallets. The transfers appeared as zero-ETH sales through a contract associated with Magic Eden’s former Ethereum marketplace. Quit subsequently said he controlled the wallet: those conspicuous transfers were an attempt to move vulnerable NFTs out of reach of attackers.
19
28
What the white-hat rescue saved—and what it did not
Working with Limit Break, the white-hat operation ultimately moved 23,155 NFTs valued at more than $5.7 million into protective custody. Reports identified a custody address beginning 0x71cf and said owners would be able to reclaim rescued assets once it was safe to do so. Protective custody is not the same as confirmation that every NFT has already been returned.
24
27
37
The rescue did not cover every loss. Reports attributed roughly 660 WETH that was not recovered in time to a related exploit path. The sources describe its status somewhat differently—some call it lost, while others say it remained at risk—so the NFT rescue should not be read as recovery of those funds.
2
8
13
Why a closed marketplace still left wallets exposed
Magic Eden said it stopped using Payment Processor V2 in October 2024 and closed its EVM marketplace in the first quarter of 2026. It identified listings made roughly February through October 2024 as potentially affected and said no live Magic Eden listings were impacted. That distinction concerns the listings; it does not mean an old approval disappeared when a listing was cancelled or the marketplace closed.
5
22
An approval is permission granted onchain to a contract. The exploit needed that existing permission, not a fresh signature from the owner. Cancelling a listing therefore does not revoke the approval, and keeping private keys on a hardware wallet does not undo authority already granted to a vulnerable contract.
7
39
What former users should check
Quit and Revoke.cash urged users to revoke affected Payment Processor V2 approvals on Ethereum and Payment Processor V3 approvals on ApeChain, using Revoke.cash or a similar tool. Magic Eden also urged former EVM users to check V2 approvals on Polygon and Base; Revoke.cash reports attacks across additional chains. Owners whose NFTs were moved into protective custody were likewise told to revoke affected approvals before reclaiming them.
22
24
35
38
The lasting lesson is about permissions, not just marketplaces: retiring a trading service or removing a sale listing does not automatically remove an approval recorded onchain.
7
39