Old NFT approvals drained in Payment Processor exploit
Attackers abused a retired Limit Break contract once used by Magic Eden, stealing about $2.8M from wallets that approved it years ago.
By Lena Hart · Published · Updated · 4 min read

A flaw in a smart contract that Magic Eden stopped using in 2024 has been used to steal NFTs and tokens from wallets that approved it long ago, Shattered reports.
What happened
From September 24, attackers exploited Limit Break's Payment Processor V2, which Magic Eden used for EVM trades from about February to October 2024. The bug let an attacker fake the sender of a forwarded transaction, moving assets without a new signature.
Wallets that had granted the contract "approve for all" permission years earlier were still exposed — even though Magic Eden had moved on.
The numbers
- About $2.8 million in assets stolen, including roughly 660 WETH not recovered.
- 23,155 NFTs worth over $5.7 million moved to a protective wallet by white-hat researchers led by Yuga Labs' 0xQuit.
Why it matters
Token approvals do not expire. When you list an NFT or trade on a marketplace, you often give a contract permanent permission to move your assets. If that contract is later found to be flawed — even after the marketplace stops using it — your wallet is still at risk.
How to protect your wallet
- Review your approvals with a tool such as Revoke.cash or your wallet's built-in permissions page.
- Revoke anything from marketplaces or apps you no longer use.
- Keep valuable NFTs in a separate wallet that never connects to trading sites.



