Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit
Magic Eden warned that NFTs listed on its EVM marketplace from about February to October 2024 may be exposed to an exploit in Limit Break’s Payment Processor V2 contract. The issue stems from lingering “approved for all” permissions that can remain active after listing, allowing the contract to move NFTs unless approvals are revoked. Magic Eden said no live listings were affected, but urged affected users to revoke the contract’s permissions on Ethereum, Polygon, and Base via Revoke.cash. Yuga Labs’ 0xQuit said an attacker used the bug to steal NFTs including Meebits, Otherdeeds, World of Women, and Desperate ApeWives. Limit Break paused V3, but V2 could not be paused, prompting a whitehat rescue that secured 23,155 NFTs worth over $5.7 million. Owners can reclaim rescued NFTs after revoking approvals, but 660 WETH were not recovered.
