Whitehats Rescue $5.7M in NFTs From Legacy Contract Exploit
Whitehats rescue 23,155 NFTs worth about $5.7M after a Magic Eden PaymentProcessorV2 exploit, while roughly 660 WETH was lost.

A whitehat team rescued 23,155 NFTs valued at more than $5.7 million after attackers began exploiting old approvals connected to Limit Break’s Payment Processor V2, a contract previously used by Magic Eden’s Ethereum marketplace. The incident turned permissions granted as far back as 2024 into an active attack surface long after Magic Eden stopped using the contract. Magic Eden said its current listings were unaffected because it abandoned Payment Processor V2 in October 2024 and later closed its EVM marketplace.
According to security researcher 0xQuit’s technical breakdown, the vulnerability allowed an attacker to exploit the contract’s handling of a trusted forwarder and impersonate an approved NFT holder during settlement. Because Payment Processor V2 could not be paused, the whitehat team used the same vulnerable execution path to move exposed NFTs into a rescue wallet before malicious actors could take them. Contributors including Coffeedev and 0xjustadev assisted with the response.
I owe everyone a proper technical breakdown of the exploit of PaymentProcessorV2 and the rescue that followed.
The short version: Payment Processor trusted an ERC-2771 style “original sender” supplied through a trusted forwarder.
That sender could be forged.
1/🧵
— Quit (@0xQuit) September 28, 2026
Old Approvals Survived Magic Eden’s EVM Exit
The first identified abuse occurred on September 24, when 305 NFTs, including Meebits, Otherdeeds, World of Women and Desperate ApeWives assets, were transferred from an approving wallet at zero purchase price. The underlying weakness was not in Ethereum or Magic Eden’s current marketplace, but in a legacy Limit Break settlement contract that still retained permissions previously granted by users.
That distinction is particularly important for users who assume closing a listing or abandoning a marketplace automatically removes contract permissions. ERC-721 “approve for all” permissions can remain active until explicitly revoked, leaving dormant integrations exploitable years later if their contracts contain vulnerabilities. Similar legacy-code risk has surfaced elsewhere in DeFi, including a Balancer V1 pool exploit involving an older contract design. A discontinued front end does not necessarily eliminate the authority previously granted to its underlying contracts.
Magic Eden said users who listed EVM NFTs through the affected infrastructure between roughly February and October 2024 should revoke Payment Processor V2 approvals on Ethereum, Polygon and Base. Rescued assets can be reclaimed after the dangerous permissions have been removed. The recovery process is deliberately conditioned on revocation so returned NFTs cannot immediately be taken again through the same approval path.
WETH Losses Complicate the Rescue Total
The incident was not limited to NFTs. 0xQuit initially reported that 660 WETH was exposed through a related reverse version of the exploit and could not be rescued in time. Later transaction-level analysis counted 542.1 WETH actually removed through Payment Processor V2 between September 25 and September 29. Those figures measure different stages of the incident: 660 WETH was the initial exposure estimate, while 542.1 WETH represents later observed transfers.
Of that amount, 282.7 WETH was captured by an MEV operator that subsequently agreed to return 90% to affected users, according to the on-chain investigation. Other funds remained in attacker-linked addresses or moved through privacy infrastructure. That makes it premature to characterize the entire original WETH exposure as permanently lost, particularly while recovery efforts and tracing remain active.
The rescue also did not permanently close the vulnerability. PublicAML identified another wallet receiving about 30,800 NFTs from 2,697 wallets on September 26 and 27, after the initial whitehat operation had concluded. The episode adds to a run of incidents involving very different security boundaries, from the USM Protocol exploit to the Kelp DAO restaking incident. What makes Payment Processor V2 particularly instructive is how a deprecated contract remained dangerous because user approvals outlived the marketplace activity that originally required them.
For former Magic Eden EVM users, the practical lesson is unusually concrete: an old approval can remain meaningful long after the product behind it disappears. The $5.7 million rescue prevented thousands of NFTs from remaining exposed, but the subsequent drains show why revoking obsolete permissions, rather than merely abandoning an application, is what actually closes the wallet-level risk.
This article is for information only and is not investment advice. We report under our Editorial Policy; to flag an error, see our Corrections Policy.


