Currencies39406
Market Cap$ 2.97T+0.01%
24h Spot Volume$ 44.38B+0.35%
DominanceBTC56.70%-0.65%ETH11.03%-0.10%
ETH Gas0.07 Gwei
FeaturedEthereumPaymentsHacksWalletsNFTMagic EdenLimit Break
Sep 25, 2026
2min read
byLiam ‘Akiba’ Wright
forCryptoSlate

Revoke.cash warned on September 25 that a vulnerability in Limit Break’s Payment Processor V2 left old Magic Eden operator approvals active after the marketplace ended EVM support on March 9, 2026, and researcher 0xQuit moved 3,832 NFTs to a custody wallet in a reported whitehat rescue. Users are advised to revoke Payment Processor V2 approvals on Ethereum and Payment Processor V3 approvals on ApeChain because canceling listings or disconnecting wallets does not remove onchain permissions, highlighting a crypto NFT security risk.
See what traders are focused on
Old Magic Eden NFT approvals could still put some former users at risk months after the company closed its Ethereum marketplace. A September 25 warning from wallet security service Revoke.cash says that a vulnerability in Limit Break’s Payment Processor V2 affects wallets that still authorize the contract to move NFTs. Those approvals remain active until owners revoke them.
The notice says security researcher 0xQuit used the vulnerability to move 3,832 NFTs from approved wallets as zero ETH sales. He described the transfers as a whitehat rescue and said the assets were being held in a custody wallet until it was safe to return them The figure counts transfers reported in the notice; the service had not established how many NFTs, if any, malicious actors took
Magic Eden ended EVM marketplace support on March 9, 2026. Its listings and offers were offchain and ceased to be visible or actionable on the site. The operator approval users gave the processor exists onchain, however. Closing the marketplace did not cancel that separate permission, leaving people who have not traded there for months with a live exposure.
Which Magic Eden NFT approvals should users revoke?
Revoke.cash says users should revoke Payment Processor V2 approval on Ethereum. It also warns anyone who approved Payment Processor V3 on ApeChain to revoke that separate permission. An NFT operator approval lets a contract move assets on a wallet’s behalf. A permission granted for marketplace trading can outlast the listing that prompted it, so former users need to check the approval itself rather than their old sale history.
Canceling a listing will not protect an exposed wallet, Revoke.cash said. Its FAQ also explains that disconnecting a wallet from a website leaves onchain approvals active. The incident page includes an exploit checker so users can inspect whether their address is affected and revoke the relevant permission. The warning applies to the named processor approvals; it does not establish that losses occurred on both Ethereum and ApeChain. Revocation is a preventive step, the FAQ says: it reduces future exposure but does not retrieve assets already taken. That distinction makes checking old permissions urgent even while the full incident outcome remains unknown.
The technical details of the flaw had not been published in Revoke.cash’s September 25 notice, and the service said it remained unclear whether malicious actors had taken any NFTs. The reported rescue leaves the final loss figure unresolved. For holders with lingering approvals, the action identified in the warning is to revoke access to the affected processor contracts.