Magic Eden's Abandoned Contracts Expose Thousands of NFTs to Theft
A vulnerability in Limit Break's Payment Processor V2 protocol, which Magic Eden used to settle trades on its Ethereum-compatible marketplace between February and October 2024, was exploited by an attacker to steal thousands of NFTs.
The attack occurred when the same address pulled 305 NFTs from one wallet in three transactions, each priced at zero. The exploit was only noticed after twelve hours had passed.
In response, a whitehat rescue operation was led by Yuga Labs Vice President of Blockchain 0xQuit, who first identified the breach and later recovered more than $5.7 million worth of NFTs.
The incident highlights how permissions granted on blockchain networks can remain active long after a platform has stopped using them.