Revoke.cash logo

Magic Eden / Limit Break Hack

Check if your address is affected.

25 Sep 2026
$0 stolen
Ethereum Logo
ApeChain Logo

On 25 September 2026, security researcher 0xQuit used a vulnerability in Limit Break's Payment Processor, the NFT marketplace protocol behind Magic Eden's former Ethereum marketplace, to move 3,832 NFTs, reportedly worth around $1.4M, out of wallets that had approved Payment Processor V2 as an operator. The transfers were executed through the contract as 0 ETH sales, and 0xQuit stated that this was a whitehat rescue and that the NFTs are held in a custody wallet and will be returned once they are no longer at risk. Users have been urged to revoke approvals to Payment Processor V2 on Ethereum and Payment Processor V3 on ApeChain, as cancelling listings or bumping the master nonce does not protect against the issue. Details of the vulnerability have not been published yet, and it is not yet clear whether any NFTs were taken by malicious actors. This entry will be updated as more information becomes known.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits