Magic Eden discontinued its EVM marketplace and stopped using Limit Break’s Payment Processor V2 in October 2024. However, the permissions that users had granted to that contract were never automatically withdrawn. When the processor was compromised this week, those lingering approvals re-enabled the exploit, putting a large pool of NFTs at risk.

Scale of the Exposure

The vulnerability affected assets from high-profile collections such as Meebits, Otherdeeds and World of Women. Security analysts estimated that more than $5.7 million worth of NFTs remained exposed because the old approvals were still valid on several networks, including Ethereum, Polygon and Base. The exploit also created a related pathway that could have jeopardized hundreds of WETH, indicating the issue was not limited to non-fungible tokens.

White-Hat Intervention

A coordinated rescue operation by a white-hat researcher intervened before any theft could occur. The team transferred 23,155 NFTs to a safe address, effectively securing the entire at-risk value. The rescued assets will be returned to their owners once the affected users revoke the outdated approval.

Why Revoking Permissions Is Crucial

Token approvals function like permanent delegations: once a wallet grants a contract the right to move assets, that right persists until the owner explicitly cancels it. Shutting down a platform, switching services, or abandoning a user interface does not automatically nullify those permissions. Consequently, assets can remain vulnerable long after the original application disappears.

Recommended User Action

Magic Eden advises anyone who interacted with its EVM marketplace before the shutdown to revoke the Payment Processor V2 allowance on the supported chains. Users can do this through their wallet interface or a reputable permission-management tool. Prompt revocation will prevent the same contract from acting on their holdings in the future.

Why it matters

The incident underscores a broader security challenge in decentralized finance: on-chain approvals are immutable unless the holder takes explicit steps to withdraw them. As more platforms evolve or cease operations, the risk of legacy permissions being exploited grows. Regularly auditing and cleaning up token allowances is becoming a necessary habit for anyone holding NFTs or other digital assets on public blockchains.