Magic Eden issued a warning regarding potential exposure for non-fungible tokens listed on its now-closed Ethereum Virtual Machine (EVM) marketplace. The risk stems from an exploit in Payment Processor V2, an NFT trading protocol developed by Limit Break, which Magic Eden used to settle trades until it stopped using the contract in October 2024 and shut down the EVM marketplace entirely in early 2026. Although no live listings were impacted, lingering "approved for all" permissions granted during previous transactions remain active unless revoked. Users who traded on the platform are urged to revoke these approvals on Ethereum, Polygon, and Base via Revoke.cash, noting that this action will not return assets already moved.
Yuga Labs Vice President of Blockchain, known as 0xQuit, reported that an attacker exploited the bug to steal specific collections including Meebits, Otherdeeds, World of Women, and Desperate ApeWives. While Limit Break paused the vulnerable Payment Processor V3, V2 could not be paused, necessitating a whitehat rescue operation. This intervention successfully recovered 23,155 NFTs valued at over $5.7 million, though 660 wrapped Ethereum (WETH) was lost due to a reverse version of the exploit. Owners can reclaim rescued NFTs after revoking their approvals. This incident follows Magic Eden’s strategic shift away from Ethereum and Bitcoin support in February to focus on Solana and its Dicey crypto casino.
The persistence of security risks from deprecated infrastructure highlights a critical gap in how marketplaces manage legacy smart contract interactions. Even after Magic Eden ceased operations on its EVM marketplace, the underlying technical debt remained because user-granted allowances do not automatically expire when a platform shuts down. This situation underscores the necessity for users to actively audit and revoke permissions for inactive protocols, as passive reliance on platform maintenance schedules leaves assets vulnerable to exploits discovered long after service termination.
From an operational risk perspective, the inability to pause Payment Processor V2 contrasts sharply with the successful mitigation of V3, revealing inconsistencies in emergency response capabilities across different versions of the same protocol. The loss of 660 WETH despite a large-scale whitehat rescue demonstrates that reactive measures have limits when architectural flaws prevent immediate contract suspension. This event serves as a cautionary tale for institutional adopters and retail users alike, emphasizing that asset safety depends not only on current platform activity but also on the hygiene of historical contract approvals.


