Magic Eden’s EVM-compatible marketplace operated for a limited period in 2024 before the platform shifted focus to Solana-based services and discontinued the multichain wallet in early 2026. During its brief run, users who listed NFTs granted a contract broad transfer rights, a practice that leaves those permissions active until manually withdrawn.

Exploit details

A vulnerability in Limit Break’s Payment Processor V2 was exploited to move assets without owner consent. The flaw allowed an attacker to extract a range of high-profile NFTs, including ten Meebits, fifty Otherdeeds, ten World of Women pieces, and 235 Desperate ApeWives. Because the V2 contract could not be paused, the breach persisted until a white-hat intervention occurred.

White-hat response and losses

The rescue operation, coordinated by Yuga Labs’ blockchain lead known as 0xQuit, transferred more than twenty-three thousand NFTs to a secure holding, estimating a total value exceeding $5.7 million. However, the effort could not recover 660 wrapped ETH (WETH) that had already been siphoned via a reverse variant of the same exploit.

User remediation steps

Magic Eden has advised anyone who listed or traded on the now-defunct marketplace to remove the "approved for all" permissions granted to the V2 contract. This can be done on Ethereum, Polygon and Base through services such as Revoke.cash. Revoking the approvals does not restore assets that have already left the wallet, but it prevents further unauthorized transfers.

Platform shift and broader context

The company had already ceased support for Ethereum and Bitcoin in February to concentrate on Solana and its crypto casino offering, Dicey. The timing of this incident coincides with a series of high-profile attacks, including a recent theft of over $380 million from the Bitget exchange.

Why it matters

The episode highlights the lingering risk of open contract approvals, especially when platforms discontinue support for a blockchain. Users who interact with cross-chain marketplaces must remain vigilant about permission management, as dormant approvals can become attack vectors long after a service ends. The incident also underscores the importance of rapid white-hat interventions in limiting financial damage during smart-contract exploits.

Why it matters

Legacy approvals can expose assets to theft even after a marketplace shuts down, emphasizing the need for ongoing security hygiene across all blockchain interactions.