Revoke.cash logo

Magic Eden / Limit Break Hack

Check if your address is affected.

24 Sep 2026
$2.8M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Robinhood Chain Logo
Berachain Logo
ApeChain Logo

Payment Processor is an NFT trading protocol maintained by Limit Break. Magic Eden adopted Payment Processor V2 to settle trades on its EVM marketplace in 2024 and stopped using it in October 2024, but approvals granted back then remained active. Payment Processor supports meta-transactions through trusted forwarder contracts, which anyone can deploy. By combining such a forwarder with specially crafted calldata, an attacker can make Payment Processor treat any other wallet as the counterparty of a trade, without that wallet signing anything. Cancelling listings or invalidating signatures does not help, because the attack only relies on the wallet's approval to the contract.

The flaw can be abused in two ways. For wallets that allowed Payment Processor to transfer their NFTs, the attacker accepts their own zero-price offer in that wallet's name, moving the NFTs to themselves for free. For wallets that approved WETH or other tokens to make offers, the attacker lists a worthless NFT and forces the wallet to buy it, moving the approved tokens to the attacker.

The first known attack happened on 24 September 2026, when an attacker stole over 300 NFTs on Ethereum and sold them into marketplace bids. It was reported to Yuga Labs' 0xQuit more than 12 hours later. After the vulnerable contracts were named publicly the next morning, other attackers quickly copied the technique. They drained around 580 WETH along with USDC, POL and other tokens across Ethereum, Polygon, Base, Arbitrum and ApeChain, and took thousands more NFTs. Much of the loot was sold into marketplace bids or moved through mixers, bridges and exchanges. The largest single drain, around 280 WETH, was made by an MEV bot that copied another attacker's transaction. As of 25 September 12:00 UTC the stolen assets were worth at least $2.8M, and attacks were still ongoing.

To limit the damage, 0xQuit and other researchers used the same vulnerability to move over 23,000 NFTs worth more than $5.7M on Ethereum and ApeChain into a custody wallet (0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33). According to 0xQuit, owners will be able to claim their NFTs back after revoking their approvals. The rescue could not protect token approvals in time, which is where most of the stolen funds came from.

Payment Processor V2 has no pause or upgrade mechanism, so it stays vulnerable on every chain it is deployed on. Limit Break paused Payment Processor V3, which has the same flaw, on every chain except ApeChain, where an earlier fee setting keeps it usable until 30 November 2026. Magic Eden has confirmed the issue and urged users to revoke, while Limit Break has not published a statement yet. Anyone who approved either contract on any chain should revoke those approvals, including token approvals such as WETH. Revoking protects the assets still in your wallet but does not recover assets that were already taken.

This entry will be updated as more information becomes known.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits