In Brief:
- After an exploit of Limit Break’s Payment Processor V2 contract, the contract Magic Eden once used to settle EVM trades, OpenSea has flagged more than 3,000 items as stolen and stopped them from trading.
- Revoke.cash says attackers took NFTs and tokens worth at least $2.8 million by abusing old approvals that users never turned off.
- A whitehat team led by 0xQuit of Yuga Labs recovered 23,155 NFTs worth more than $5.7 million, and a claim site is now live.
OpenSea's Chris Maddern said the marketplace has flagged more than 3,000 NFTs as stolen and blocked them from trading following a security incident involving Magic Eden and Limit Break.
“we’re aware of a security incident affecting Magic Eden & Limit Break,” Maddern said. “the team is working to make sure that these items are not able to be re-sold on @opensea.” He added that “so far over 3,000 items have been marked as stolen & prevented trading.”
a short update on the limit break / magic eden incident response
as a reminder, no @opensea systems or contracts are affected
> known-impacted ERC721 NFTs have been flagged on OpenSea & cannot be sold
> newly exploited NFTs are automatically flagged (limiting exploiter accessChris MaddernView on X ↗
In a later post, Maddern said “no @opensea systems or contracts are affected.” He also said “known-impacted ERC721 NFTs have been flagged on OpenSea & cannot be sold” and that “newly exploited NFTs are automatically flagged.”
A new exploit built on old approvals
The bug is in Payment Processor V2, a contract maintained by Limit Break. From February to October 2024, Magic Eden relied on it to settle trades on EVM networks, and then it stopped using it. In the first quarter of 2026, Magic Eden closed its EVM marketplace altogether.
The approvals users gave the contract during those months were never removed on-chain. From about 9 a.m. EST on Sept. 24, attackers used a bug that let them act for any wallet that had approved the protocol.
That let them take NFTs without paying. They also emptied approved tokens by making wallets buy worthless NFTs. One address took 305 NFTs from a single wallet in three transactions, and each one was recorded as a “sale” at a price of zero.
According to 0xQuit, Yuga Labs vice president of blockchain, the first reported theft included 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives.
Revoke.cash said attackers have taken NFTs and tokens worth at least $2.8 million across Ethereum, Polygon, Base, Arbitrum and ApeChain, and that the thefts were still going on. Users can test their addresses with an exploit checker Revoke.cash has put live.
The whitehat rescue
V2 cannot be paused or fixed, so it is still vulnerable. Payment Processor V3 had the same flaw, and Limit Break paused it on every chain except ApeChain, where V3 stays usable until Nov. 30, 2026.
Because V2 was still open, a group of security researchers used the same bug to move exposed NFTs into a wallet they control. 0xQuit ran the operation with Coffeedev, 0xjustadev and whiteoakkong.
“All in all, we rescued 23,155 NFTs worth north of $5.7M USD,” 0xQuit said.
Some assets were lost. “660 WETH was at risk, which we unfortunately were not fast enough to recover,” 0xQuit said. He said the exploit could be run in reverse to pull WETH.
An earlier count put the rescue at 3,832 NFTs. That number likely came from a tally taken partway through the operation.
Claims and revoking approvals
The only official claim site is nftsaresafu.xyz. At the latest count, 2,357 of the 26,448 recovered assets had been claimed.
Owners have to revoke their Payment Processor approval before they can claim. 0xQuit warned that transfer validator rules may stop holders of ERC721C or ERC1155C collections from claiming.
The contracts to revoke are 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 on Ethereum, Polygon and Base, and 0x9a1D00000000fC540e2000560054812452eB5366 on ApeChain. Arbitrum should also be checked. The permissions include “approved for all” NFT approvals and token approvals for WETH, WAPE, USDC or APE. Wallets usually show the contract as “Limit Break: Payment Processor.”
Cancelling listings won’t protect you, Revoke.cash said, because the attack only needs the approval.
Magic Eden warned that NFTs listed on its EVM marketplace before October 2024 could be affected, while newer listings are safe. Co-founder and CEO Jack Lu said the incident involves Limit Break’s trading protocol and contracts, which Magic Eden stopped using two years ago.
Revoking the approval protects what is still in a wallet, but it won’t recover assets that have already been taken.


















STAY ALWAYS UP TO DATE