Magic Eden Users Exposed by Limit Break Vulnerability
A vulnerability in Limit Break's Payment Processor V2 has left some former Magic Eden NFT users at risk of asset loss. The issue affects wallets that still authorize the contract to move NFTs, which remains active until owners revoke them.
According to a September 25 warning from wallet security service Revoke.cash, a security researcher known as 0xQuit used this vulnerability to move 3,832 NFTs from approved wallets. The transfers were described as a 'whitehat rescue' and the assets are being held in a custody wallet until it is safe to return them.
Magic Eden ended its Ethereum marketplace support on March 9, but the operator approval users gave the processor exists onchain. This means that people who have not traded there for months may still be exposed if they don't revoke their permission.
Revoke.cash advises users to revoke Payment Processor V2 approval on Ethereum and also warns anyone who approved Payment Processor V3 on ApeChain to do the same. Canceling a listing will not protect an exposed wallet, and disconnecting a wallet from a website leaves onchain approvals active.