Pond Street Ledger

A Flaw in Old Magic Eden Listings Sent 23,155 NFTs Into Whitehat Custody

A vulnerability in Limit Break's Payment Processor V2 left dormant Magic Eden listings on Ethereum exposed. White hats moved more than $5.7m of NFTs out of reach before attackers could, and holders still need to revoke the approvals.

✓ 201.efrogs.eth2026-09-264 min
Sources: Cointelegraph, Decrypt, The Defiant

A flaw in Limit Break's Payment Processor V2, a contract used to settle NFT trades, left old listings on the Magic Eden marketplace on Ethereum open to exploitation, according to reports from Decrypt and The Defiant. White hat researchers swept the vulnerable assets into protective custody before attackers could drain them. Yuga Labs' 0xQuit said 23,155 NFTs worth more than $5.7m were secured, and that the items will be returned to their owners once the risk has passed.

Cointelegraph reported a separate tally of 3,832 NFTs placed in protective custody during the same episode. The figures cover different scopes of the rescue rather than contradicting each other, and the headline number cited by 0xQuit is the larger one.

What actually went wrong

The problem is an approval, not a wallet compromise. To list an NFT for sale on a marketplace, a holder grants that marketplace's settlement contract permission to move the item out of their wallet when a buyer pays. That permission does not expire when the listing does. It sits on chain until the holder revokes it, which almost nobody does.

When a bug is later found in the contract holding those permissions, every wallet that ever listed through it is exposed, including people who sold nothing, moved on years ago and no longer think of themselves as marketplace users. That is the shape of this incident: the listings were legacy, the approvals were not.

What holders have to do

Revoke. Both reports are explicit that the whitehat sweep does not fix the underlying exposure for anyone whose assets were not swept. Holders need to revoke the vulnerable contracts' permissions over both NFTs and tokens, using a wallet's own permissions screen or a revocation tool they already trust. Approvals are per contract and per collection, so a single revocation rarely covers everything.

This is also the moment when the impersonators arrive. A high-profile approval bug produces a predictable wave of accounts offering a link that will supposedly check or fix your wallet, and the link drains it instead. Nothing in a legitimate revocation requires a seed phrase, and nothing requires signing a transaction sent to you by a stranger.

The custody question

Whitehat rescues work, and they are also uncomfortable. Someone other than the owner takes control of the asset, and the owner is asked to trust that it comes back. In this case the person running the operation is publicly identified and works at Yuga Labs, which is about as good as the trust assumption gets, but the general pattern has no enforcement behind it beyond reputation.

The recurring lesson is about the permissions layer rather than any one marketplace. Approvals granted to a settlement contract are a standing claim on an asset, and their risk profile changes every time someone finds a bug in code that has been sitting untouched for years. What to watch is how many of the 23,155 items are actually returned, and how quickly.

We report facts in our own words and link to the reporting we drew them from. We do not reproduce a source's prose, headline or images. Nothing here is investment advice.