Magic Eden ended support for its Ethereum-based marketplace on 9 March 2026. While the website stopped showing listings, the smart-contract permissions that traders granted to the platform’s payment processors stayed on the blockchain. Those lingering approvals allow the contracts to move NFTs on behalf of the wallet owner.
White-hat intervention
Security service Revoke.cash issued a warning on 25 September, outlining a vulnerability in Limit Break’s Payment Processor V2. Researcher known as 0xQuit exploited the flaw to transfer 3,832 NFTs from wallets that still held the approval, recording the moves as zero-ETH sales. The assets were placed in a custodial wallet pending safe return. The notice did not confirm whether any malicious actors succeeded in stealing additional NFTs.
Impact on users
Wallets that approved the processor before the marketplace closure remain exposed. Disconnecting a wallet from the site or cancelling a listing does not clear the on-chain permission. Consequently, any address that still authorises the processor can have its NFTs moved without further interaction from the owner.
Recommended mitigation steps
Revoke.cash advises all affected users to revoke the Payment Processor V2 approval on Ethereum. The service also flags a separate approval for Payment Processor V3 on the ApeChain network, which should be revoked in the same manner. Revocation lowers future risk but cannot retrieve NFTs already transferred. Revoke.cash provides an online checker where users can paste their address to see if the vulnerable approvals are present and revoke them directly.
Why it matters
The incident highlights how on-chain authorisations can outlive the services that created them, keeping users at risk long after a platform shuts down. Prompt revocation of stale permissions is essential to safeguard NFT holdings across multiple chains, especially as white-hat rescues may expose the scale of potential losses.



