BlockBeats news, September 25: Magic Eden posted a statement saying that this vulnerability occurred in the NFT trading protocol Payment Processor V2 maintained by Limit Break. Magic Eden adopted this protocol in 2024 to handle transaction settlement on EVM networks, but stopped using V2 in October 2024 and fully shut down its EVM marketplace in Q1 2026, so NFTs currently still listed on Magic Eden were not affected by this vulnerability.
NFTs listed through its EVM marketplace between approximately February and October 2024 may be affected, while listings after October 2024 are in principle unaffected. The platform is contacting the protocol owner and maintainer Limit Break to study other risk mitigation measures, including pausing protocol transfers, and will continue to investigate the actual scope of impact.
Magic Eden reminds users who have previously listed or traded NFTs on its EVM marketplace that they should revoke relevant contract approvals on Ethereum, Polygon, and Base networks. Users can use revoke.cash to filter the address and revoke all NFT approvals marked as "approved for all." Magic Eden emphasizes that revoking approvals cannot recover assets that have already been transferred.
According to previous reports, Yuga Labs blockchain vice president Quit posted that at 9 AM Eastern Time today, attackers exploited the Payment Processor V2 vulnerability to steal a large number of NFTs. After contacting the LimitBreak team, the latter quickly paused the similarly affected Payment Processor V3. However, V2 could not be paused, and V3 on ApeChain was also temporarily unable to be paused, so the team carried out a white-hat operation, transferring and protecting a total of 23,155 NFTs, worth more than $5.7 million.

