Back to collection
Research

Legacy Magic Eden Approvals Exposed Wallets to NFT Theft

Revoke.cash says exploitation of the legacy Payment Processor V2 contract began on September 24 and that users with old approvals needed to revoke them.

A revocation switch severs a red legacy permission chain while digital collectible tiles remain protected behind a shield.
Technical illustration

Revoke.cash reported that attackers began exploiting Limit Break’s legacy Payment Processor V2 contract on September 24, targeting wallets that had previously approved the contract while using Magic Eden. Because the old contract could not be paused or upgraded, the risk persisted for wallets whose approvals remained active even if they no longer used the marketplace.

The incident page attributes at least $2.8 million in thefts to the exploit and says more than 23,000 NFTs worth over $5.7 million were moved to safety. Those totals are Revoke.cash estimates, not independently audited figures. Revoking an approval can block later transfers through that permission, but it cannot recover assets already taken.

References