Magic Eden Users Urged to Revoke Legacy Approvals After Limit Break Exploit

Magic Eden users with legacy EVM marketplace listings are urged to revoke Limit Break V2 approvals after a cross-chain exploit stole at least $2.8 million.

Magic Eden Users Urged to Revoke Legacy Approvals After Limit Break Exploit

Magic Eden urged users of its former EVM marketplace to revoke legacy Limit Break Payment Processor V2 approvals on Ethereum, Polygon and Base.

On Sept. 26, Revoke.cash reported at least $2.8 million in NFTs and tokens stolen across Ethereum, Polygon, Base, Arbitrum and ApeChain.

Revoke.cash also reported that white-hat researchers rescued more than 23,000 NFTs valued above $5.7 million. Revoking an approval does not recover assets already transferred, according to TokenPost.

Limit Break V2 exploit reached five networks

Attackers began exploiting a vulnerability in Limit Break Payment Processor V2 on Sept. 24, according to the Revoke.cash Exploit Database. The processor retained permissions granted by users of Magic Eden’s former Ethereum marketplace, turning old approvals into the route used in the attack.

Revoke.cash said the thefts occurred across Ethereum, Polygon, Base, Arbitrum and ApeChain. Its reported $2.8 million loss figure is described as a minimum, while the white-hat recovery operation was led by security researcher 0xQuit.

Even when a listed asset has not been transferred, users with a remaining approval may still need to act; the stolen and rescued totals alone do not establish that every exposed asset was secured.

2024 Magic Eden listings left approvals

The vulnerable processor was used for Magic Eden’s EVM marketplace in 2024. The platform said listings made approximately between February and October 2024 could be affected, while current live Magic Eden listings were not impacted, as reported by Cointelegraph.

The warning is therefore directed at users who interacted with the earlier marketplace rather than at all current Magic Eden activity. Those users should review and revoke Limit Break Payment Processor V2 permissions on Ethereum, Polygon and Base; that step addresses the lingering approval but cannot recover assets already transferred in the exploit.

Investment Disclaimer

Share this story

X LinkedIn

Related Stories