NFT

Magic Eden flags Ethereum NFT drain tied to Limit Break Payment Processor V2

Magic Eden said an exploit affecting Limit Break’s Payment Processor V2 could allow attackers to drain NFTs from wallets that interacted with the marketplace’s earlier Ethereum setup. The company’s interim update urged users to revoke approvals, signaling that the issue centers on old permissions rather than an active Magic Eden trading flow.

The affected contract was used for Ethereum NFT trades in 2024, according to the surrounding reporting. Magic Eden said no live listings were impacted, which matters because the vulnerable permissions appear to be tied to prior wallet approvals rather than current marketplace orders.

Limit Break’s Payment Processor V2 sat behind settlement for Magic Eden’s Ethereum marketplace activity before the platform stopped using it. That distinction is important: the exploit is being discussed in connection with a contract Magic Eden no longer relies on, but approvals granted by users can remain active even after a platform moves on.

Why old approvals still mattered

The reported risk comes from the way NFT permissions work on Ethereum. When users grant broad spending approvals to a contract, those approvals can remain in place until they are revoked. In this case, that left some older wallets exposed to a flaw in a contract no longer in active use by Magic Eden.

Public reporting on the incident described a wider rescue effort that followed the initial drain, with whitehat responders working to secure exposed NFTs. Those accounts suggested the incident extended beyond a single wallet, though the exact scope belongs to the broader incident report rather than Magic Eden’s brief update.

Magic Eden’s message focused on immediate user action: revoke approvals where relevant. That is a standard response when a contract-level issue can still affect wallets that approved it in the past, even if the marketplace itself is no longer routing trades through it.

The update did not provide a full loss estimate or a complete accounting of affected wallets. For now, the clearest confirmed point is that the flaw sits in Limit Break’s Payment Processor V2 and that Magic Eden says the exposure relates to past Ethereum marketplace activity, not live listings.