{"investigation":{"slug":"limit-break-payment-processor-v2-magic-eden-nft-exploit","entity_name":"Limit Break Payment Processor V2 — Magic Eden NFT Exploit","trust_score":5,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"draft","content_type":"investigation","summary":"On September 24–25, 2026, attackers exploited a critical vulnerability in Limit Break's Payment Processor V2 smart contract — formerly used by Magic Eden's now-defunct Ethereum EVM marketplace — to steal at least $2.8 million in NFTs and tokens from wallets holding legacy approvals dating to 2024. A white-hat rescue led by Yuga Labs' blockchain VP 0xQuit secured 23,155 NFTs valued at approximately $5.7 million before further damage could occur, but roughly 660 WETH (approximately $1.7 million) was not recovered in time. Because the contract has no pause or upgrade mechanism, the vulnerability remains permanently live on every chain where it is deployed.","sections":[{"content":"On September 24, 2026, an attacker began exploiting a critical flaw in Limit Break's Payment Processor V2 (contract address 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834), an NFT trading settlement contract that Magic Eden had used to power its Ethereum EVM marketplace from approximately February 2024 to October 2024. Magic Eden shut down its EVM marketplace entirely in Q1 2026, but approvals users had granted to the Payment Processor V2 contract remained active on-chain. By combining a freely deployable trusted-forwarder contract with specially crafted calldata, attackers were able to make the Payment Processor treat any wallet as a counterparty to a trade without that wallet signing anything, allowing unauthorized asset transfers. The first wave targeted approximately 305 NFTs. After the vulnerable contract address was publicly named on the morning of September 25, copycat attackers drained additional assets across Ethereum, Polygon, Base, Arbitrum, ApeChain, and other networks. As of 12:00 UTC on September 25, confirmed stolen assets totaled at least $2.8 million and attacks were reportedly still ongoing at that time, according to Revoke.cash's incident tracker.","heading":"Incident Overview","sources":[{"url":"https://revoke.cash/exploits/magic-eden?chainId=1","name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"research","credibility":2},{"url":"https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874","name":"Magic Eden legacy approvals leave $5.7 million in NFTs exposed to exploit before rescue — The Block","type":"news_article","credibility":2},{"url":"https://decrypt.co/379342/magic-eden-old-ethereum-nft-listings-exposed-exploit","name":"Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit — Decrypt","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Payment Processor V2 supports meta-transactions via trusted-forwarder contracts. The EIP-2771 trusted-forwarder pattern appends the original sender's address to calldata, and the Payment Processor reads this appended value as the authoritative counterparty. The flaw is that anyone can deploy a conformant forwarder contract; there is no allow-list or deployment restriction enforced by the Payment Processor itself. An attacker can therefore deploy their own forwarder, craft calldata that names an arbitrary victim wallet as the counterparty, and cause the Payment Processor to execute a trade on behalf of that victim wallet without any signature from the victim. For wallets that granted an NFT 'approved for all' permission to the Payment Processor, the attacker can accept their own zero-price offer in the victim's name, transferring the NFTs to themselves for free. The same attack vector operates in reverse for WETH: the attacker can force victim wallets to 'buy' worthless dummy NFTs, draining WETH balances through the pre-existing token approval. Cancelling listings or invalidating signatures provides no protection, because the attack relies solely on the wallet's on-chain approval to the contract — not on any listing state. Payment Processor V2 was deployed without a pause function or an upgradeable proxy architecture, meaning the vulnerability cannot be patched or disabled by Limit Break. Limit Break did pause Payment Processor V3 (0x9a1D00000000fC540e2000560054812452eB5366) on most chains after being alerted, but V3 remained unpaused on ApeChain as of initial reporting, with a stated pause deadline of November 30, 2026.","heading":"Vulnerability Technical Analysis","sources":[{"url":"https://revoke.cash/exploits/magic-eden?chainId=1","name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"research","credibility":2},{"url":"https://cryptoticker.io/en/magic-eden-limit-break-exploit-weth-nfts-revoke-approvals/","name":"Magic Eden and Limit Break exploit: WETH and NFTs drained — CryptoTicker","type":"news_article","credibility":2},{"url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/","name":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs, Says 660 WETH Lost — CryptoTimes","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Multiple sources report differing loss figures reflecting different measurement windows and methodologies. The earliest confirmed malicious activity, on September 24, involved the theft of approximately 305 NFTs including 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. After the vulnerability was publicized on September 25, copycat attacks expanded losses substantially. Revoke.cash's incident tracker reported at least $2.8 million in confirmed stolen assets across all chains as of 12:00 UTC September 25, with attacks ongoing. On Ethereum specifically, CryptoTicker reported 530.7 WETH drained from 911 wallets (approximately $1.43 million), plus 8,380 USDC from 62 wallets, approximately 549,000 WILD tokens, and 12.9 APE tokens. On ApeChain, approximately 7,680 WAPE was drained from 19 wallets. A total of approximately 660 WETH (approximately $1.7 million at time of incident) was exposed through the WETH drain vector and was not recovered. 0xQuit characterized this amount as 'the $1.7M in WETH I wasn't fast enough for.' The on-chain analysis by Revoke.cash recorded 25,299 AcceptOffer and BuyListing events emitted by the Payment Processor V2 contract between September 23, 2026 12:00 UTC and September 25, 2026 12:22 UTC.","heading":"Confirmed Losses","sources":[{"url":"https://revoke.cash/exploits/magic-eden?chainId=1","name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"on_chain","credibility":2},{"url":"https://cryptoticker.io/en/magic-eden-limit-break-exploit-weth-nfts-revoke-approvals/","name":"Magic Eden and Limit Break exploit: WETH and NFTs drained — CryptoTicker","type":"news_article","credibility":2},{"url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/","name":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs, Says 660 WETH Lost — CryptoTimes","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/limit-break-on-ethereum-under-attack-1-7m-in-nfts-stolen","name":"Limit Break on Ethereum Under Attack, $1.7 Million in NFTs Stolen — KuCoin","type":"news_article","credibility":2}],"severity":"critical"},{"content":"0xQuit, identified as VP of Blockchain at Yuga Labs, led a white-hat rescue operation after being contacted approximately 12 hours after initial malicious activity began. Beginning at approximately 05:46:47 UTC on September 25, 0xQuit's team used the same exploit mechanism — deploying a trusted forwarder and leveraging existing approvals — to move vulnerable NFTs into a custody rescue wallet (0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33) before further attackers could drain them. At 06:47:59 UTC, 0xQuit publicly confirmed the operation was white-hat. At 09:06 UTC, 0xQuit published a detailed account on social media. 0xQuit credited team members @Boomskite, @coffeedev, @0xjustadev, and @whiteoakkong for their roles in the operation. The rescue wallet accumulated 23,155 NFTs valued at over $5.7 million across Ethereum and ApeChain. Collections represented in the rescue wallet included Art Blocks (166 pieces), Nakamigos (113), Cool Cats (42), BAYC tokens (16), and numerous other Yuga Labs ecosystem collections. 0xQuit stated that all rescued assets would be returned to their rightful owners after those owners revoked their approvals to the vulnerable contract. The rescue operation could not recover WETH drained through the token approval vector, as those funds were already moved before intervention.","heading":"White-Hat Rescue Operation","sources":[{"url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/","name":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs, Says 660 WETH Lost — CryptoTimes","type":"news_article","credibility":2},{"url":"https://news.bitcoin.com/security/white-hats-swipe-5-7m-in-nfts-before-attackers-get-their-shot/","name":"White Hats Swipe $5.7M in NFTs Before Attackers Get Their Shot — Bitcoin.com News","type":"news_article","credibility":2},{"url":"https://www.gizmotimes.com/blockchain/nft/0xquit-rescues-nfts-limit-break-exploit/51465","name":"How 0xQuit Rescued $5.7M in NFTs — GizmoTimes","type":"news_article","credibility":2},{"url":"https://cryptobriefing.com/whitehats-rescue-5-7-million-in-nfts-after-limit-break-payment-processor-exploit/","name":"Whitehats rescue $5.7 million in NFTs after Limit Break Payment Processor exploit — Crypto Briefing","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Any wallet that approved the Limit Break Payment Processor V2 contract (0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834) or V3 contract (0x9a1D00000000fC540e2000560054812452eB5366) at any time remains at risk if those approvals have not been revoked. The primary exposure window for Magic Eden EVM marketplace users is February 2024 to October 2024. The contracts were also integrated by Mintify and the Otherside marketplace, meaning users of those platforms who granted approvals are also affected. Affected chains include at minimum: Ethereum, Polygon, Base, Arbitrum, ApeChain, BNB Chain, Optimism, Avalanche, Robinhood Chain, and Berachain. Magic Eden's official statement confirmed that no live Magic Eden listings were impacted, as the platform had ceased using V2 in October 2024 and shut down its EVM marketplace entirely in Q1 2026. However, the on-chain approvals granted by users during the active period persist indefinitely unless explicitly revoked by each wallet. Revoking approvals protects remaining assets but cannot recover assets that have already been transferred.","heading":"Scope of Exposure — Affected Wallets and Chains","sources":[{"url":"https://x.com/MagicEden/status/2103435423389241569","name":"Magic Eden official statement — X (formerly Twitter)","type":"official","credibility":1},{"url":"https://revoke.cash/exploits/magic-eden?chainId=1","name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"research","credibility":2},{"url":"https://decrypt.co/379342/magic-eden-old-ethereum-nft-listings-exposed-exploit","name":"Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit — Decrypt","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Magic Eden published an interim statement at approximately 10:44 UTC on September 25 confirming: the incident involved Payment Processor V2, a protocol built and maintained by Limit Break; Magic Eden adopted it to settle EVM trades in 2024; Magic Eden stopped using it in October 2024 and ceased its EVM marketplace in Q1 2026; and no live Magic Eden listings were impacted. Magic Eden CEO Jack Lu separately emphasized that the marketplace itself was not attacked — the incident concerned Limit Break's protocol contracts. Magic Eden thanked 0xQuit for the rescue operation and confirmed it had contacted Limit Break about pause options. Limit Break paused Payment Processor V3 on most chains after being alerted by 0xQuit, but had not issued an independent public statement as of initial reporting at 10:39 UTC on September 25. Limit Break's V3 pause covered all chains except ApeChain, where a pause deadline of November 30, 2026 was communicated. V2 was not and cannot be paused due to the absence of any administrative mechanism in the deployed contract.","heading":"Institutional Response","sources":[{"url":"https://x.com/MagicEden/status/2103435423389241569","name":"Magic Eden official statement — X (formerly Twitter)","type":"official","credibility":1},{"url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/","name":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs, Says 660 WETH Lost — CryptoTimes","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/magic-eden-clarifies-nft-vulnerability-impact-advises-users-to-revoke-contract-approvals","name":"Magic Eden Clarifies the Impact of the NFT Vulnerability and Advises Users to Revoke Contract Approvals — KuCoin","type":"news_article","credibility":2}],"severity":"high"},{"content":"The Payment Processor V2 contract is immutable and unpauseable. The vulnerability is fully disclosed and publicly documented as of September 25, 2026. Any wallet that has ever approved the contract and has not yet revoked that approval remains permanently vulnerable to asset drain, on every chain where the contract is deployed, for as long as the wallet holds assets and the approval persists. Limit Break cannot patch, upgrade, or disable V2. The only mitigation available to affected wallets is to revoke all approvals granted to the contract address on each affected chain. Revoke.cash provides a purpose-built checker for this incident at https://revoke.cash/exploits/magic-eden. Revocation of approvals does not recover already-stolen assets. Payment Processor V3, while paused by Limit Break on most chains, contains the same underlying flaw and carries similar residual risk on any chain where it remains unpaused.","heading":"Permanent Residual Risk","sources":[{"url":"https://revoke.cash/exploits/magic-eden?chainId=1","name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"research","credibility":2},{"url":"https://panews.io/articles/01a0d829-657c-705c-835a-d2b9de6fac64","name":"Magic Eden: Payment Processor V2 vulnerability does not affect existing listings; NFTs listed before October 2024 may be affected — PANews","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Published loss and rescue figures vary materially across sources due to differing measurement windows, chain coverage, and timing. Revoke.cash documented 3,832 NFTs valued around $1.4 million in its initial tracking. NFTScan reported 8,472 NFTs valued at approximately $1.72 million. 0xQuit reported rescuing 23,155 NFTs valued at over $5.7 million across Ethereum and ApeChain. Revoke.cash confirmed stolen assets of at least $2.8 million as of 12:00 UTC September 25 with attacks ongoing. The $2.8 million confirmed-stolen figure and the $5.7 million rescued figure are not mutually exclusive — they measure different things. Figures will likely be revised upward as on-chain forensics are completed. The discrepancies reflect the multi-chain, multi-wave nature of the attack rather than factual contradictions between sources.","heading":"Conflicting Loss Estimates","sources":[{"url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/","name":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs, Says 660 WETH Lost — CryptoTimes","type":"news_article","credibility":2},{"url":"https://cryptoslate.com/magic-eden-nft-approvals-risk-3832-whitehat-rescue/","name":"Old Magic Eden NFT approvals put users at risk after whitehat moves 3,832 NFTs — CryptoSlate","type":"news_article","credibility":2},{"url":"https://revoke.cash/exploits/magic-eden?chainId=1","name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"on_chain","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2024-02-01","event":"Magic Eden adopts Limit Break Payment Processor V2 to settle trades on its Ethereum EVM marketplace. Users begin granting approvals to the contract.","source":"Magic Eden official statement via X","source_url":"https://x.com/MagicEden/status/2103435423389241569"},{"date":"2024-10-01","event":"Magic Eden stops using Payment Processor V2. User approvals granted during the February–October 2024 period remain active on-chain.","source":"Magic Eden official statement via X","source_url":"https://x.com/MagicEden/status/2103435423389241569"},{"date":"2026-03-09","event":"Magic Eden shuts down its EVM marketplace entirely, but legacy on-chain approvals to Payment Processor V2 are not revoked on behalf of users.","source":"Old Magic Eden NFT approvals put users at risk — CryptoSlate","source_url":"https://cryptoslate.com/magic-eden-nft-approvals-risk-3832-whitehat-rescue/"},{"date":"2026-09-24","event":"First confirmed malicious attack: approximately 305 NFTs stolen on Ethereum including 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives.","source":"2026 Magic Eden / Limit Break Hack — Revoke.cash","source_url":"https://revoke.cash/exploits/magic-eden?chainId=1"},{"date":"2026-09-25","event":"05:46:47 UTC — First white-hat rescue transaction executed by 0xQuit's team, moving vulnerable NFTs into custody wallet 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33.","source":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/"},{"date":"2026-09-25","event":"06:31:42 UTC — NFT researcher Cirrus publicly identifies unusual transfers from wallet 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33, raising initial alarm.","source":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/"},{"date":"2026-09-25","event":"06:47:59 UTC — 0xQuit publicly confirms the rescue operation is white-hat. Vulnerability mechanism publicly named, triggering copycat attacks.","source":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/"},{"date":"2026-09-25","event":"09:06 UTC — 0xQuit publishes detailed account of rescue operation; reports 23,155 NFTs rescued worth over $5.7 million and approximately 660 WETH not recovered.","source":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/"},{"date":"2026-09-25","event":"09:11 UTC — Revoke.cash launches dedicated incident checker for the exploit.","source":"2026 Magic Eden / Limit Break Hack — Revoke.cash","source_url":"https://revoke.cash/exploits/magic-eden?chainId=1"},{"date":"2026-09-25","event":"10:39 UTC — Limit Break has paused Payment Processor V3 on most chains but has not issued an independent public statement as of this time.","source":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/"},{"date":"2026-09-25","event":"10:44 UTC — Magic Eden publishes official interim statement confirming incident details and advising users to revoke approvals on Ethereum, Polygon, and Base via Revoke.cash.","source":"Magic Eden official statement via X","source_url":"https://x.com/MagicEden/status/2103435423389241569"},{"date":"2026-09-25","event":"Revoke.cash confirms at least $2.8 million in confirmed stolen assets as of 12:00 UTC, with attacks reportedly still ongoing across multiple chains.","source":"2026 Magic Eden / Limit Break Hack — Revoke.cash","source_url":"https://revoke.cash/exploits/magic-eden?chainId=1"}],"sources_used":[{"url":"https://revoke.cash/exploits/magic-eden?chainId=1","name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"research","archive_url":"https://web.archive.org/web/20260926040914/https://revoke.cash/exploits/magic-eden?chainId=1","credibility":2,"archive_timestamp":"2026-09-26T04:09:14+00:00"},{"url":"https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874","name":"Magic Eden legacy approvals leave $5.7 million in NFTs exposed to exploit before rescue — The Block","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://decrypt.co/379342/magic-eden-old-ethereum-nft-listings-exposed-exploit","name":"Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit — Decrypt","type":"news_article","archive_url":"https://web.archive.org/web/20260926040633/https://decrypt.co/379342/magic-eden-old-ethereum-nft-listings-exposed-exploit","credibility":2,"archive_timestamp":"2026-09-26T04:06:33+00:00"},{"url":"https://x.com/MagicEden/status/2103435423389241569","name":"Magic Eden official statement — X (formerly Twitter)","type":"official","archive_url":null,"credibility":1,"archive_timestamp":null},{"url":"https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/","name":"Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs, Says 660 WETH Lost — CryptoTimes","type":"news_article","archive_url":"https://web.archive.org/web/20260926050044/https://www.cryptotimes.io/2026/09/25/limit-break-nft-exploit-yuga-labs-quit-rescues-23155-nfts-says-660-weth-lost/","credibility":2,"archive_timestamp":"2026-09-26T05:00:44+00:00"},{"url":"https://cryptoticker.io/en/magic-eden-limit-break-exploit-weth-nfts-revoke-approvals/","name":"Magic Eden and Limit Break exploit: WETH and NFTs drained — CryptoTicker","type":"news_article","archive_url":"http://web.archive.org/web/20260926062532/https://cryptoticker.io/en/magic-eden-limit-break-exploit-weth-nfts-revoke-approvals/","credibility":2,"archive_timestamp":"2026-09-26T06:25:32+00:00"},{"url":"https://cryptobriefing.com/whitehats-rescue-5-7-million-in-nfts-after-limit-break-payment-processor-exploit/","name":"Whitehats rescue $5.7 million in NFTs after Limit Break Payment Processor exploit — Crypto Briefing","type":"news_article","archive_url":"http://web.archive.org/web/20260926015322/https://cryptobriefing.com/whitehats-rescue-5-7-million-in-nfts-after-limit-break-payment-processor-exploit/","credibility":2,"archive_timestamp":"2026-09-26T01:53:22+00:00"},{"url":"https://cryptoslate.com/magic-eden-nft-approvals-risk-3832-whitehat-rescue/","name":"Old Magic Eden NFT approvals put users at risk after whitehat moves 3,832 NFTs — CryptoSlate","type":"news_article","archive_url":"https://web.archive.org/web/20260926195709/https://cryptoslate.com/magic-eden-nft-approvals-risk-3832-whitehat-rescue/","credibility":2,"archive_timestamp":"2026-09-26T19:57:09+00:00"},{"url":"https://www.gizmotimes.com/blockchain/nft/0xquit-rescues-nfts-limit-break-exploit/51465","name":"How 0xQuit Rescued $5.7M in NFTs — GizmoTimes","type":"news_article","archive_url":"https://web.archive.org/web/20260926015507/https://www.gizmotimes.com/blockchain/nft/0xquit-rescues-nfts-limit-break-exploit/51465","credibility":2,"archive_timestamp":"2026-09-26T01:55:07+00:00"},{"url":"https://www.kucoin.com/news/flash/magic-eden-clarifies-nft-vulnerability-impact-advises-users-to-revoke-contract-approvals","name":"Magic Eden Clarifies the Impact of the NFT Vulnerability and Advises Users to Revoke Contract Approvals — KuCoin","type":"news_article","archive_url":"https://web.archive.org/web/20260925234457/https://www.kucoin.com/news/flash/magic-eden-clarifies-nft-vulnerability-impact-advises-users-to-revoke-contract-approvals","credibility":2,"archive_timestamp":"2026-09-25T23:44:57+00:00"},{"url":"https://panews.io/articles/01a0d829-657c-705c-835a-d2b9de6fac64","name":"Magic Eden: Payment Processor V2 vulnerability does not affect existing listings — PANews","type":"news_article","archive_url":"https://web.archive.org/web/20260926045752/https://panews.io/articles/01a0d829-657c-705c-835a-d2b9de6fac64","credibility":2,"archive_timestamp":"2026-09-26T04:57:52+00:00"},{"url":"https://etherscan.io/address/0x9a1d00bed7cd04bcda516d721a596eb22aac6834","name":"Limit Break Payment Processor V2 contract — Etherscan","type":"on_chain","archive_url":"http://web.archive.org/web/20260415132959/https://etherscan.io/address/0x9a1d00bed7cd04bcda516d721a596eb22aac6834","credibility":1,"archive_timestamp":"2026-04-15T13:29:59+00:00"},{"url":"https://news.bitcoin.com/security/white-hats-swipe-5-7m-in-nfts-before-attackers-get-their-shot/","name":"White Hats Swipe $5.7M in NFTs Before Attackers Get Their Shot — Bitcoin.com News","type":"news_article","archive_url":"https://web.archive.org/web/20260925234229/https://news.bitcoin.com/security/white-hats-swipe-5-7m-in-nfts-before-attackers-get-their-shot/","credibility":2,"archive_timestamp":"2026-09-25T23:42:29+00:00"},{"url":"https://panews.io/articles/01a0d7e5-a691-715a-ae1c-5303203c7c4e","name":"Yuga Labs Executive: Payment Processor Vulnerability Affected Over 23,000 NFTs — PANews","type":"news_article","archive_url":"https://web.archive.org/web/20260926045536/https://panews.io/articles/01a0d7e5-a691-715a-ae1c-5303203c7c4e","credibility":2,"archive_timestamp":"2026-09-26T04:55:36+00:00"},{"url":"https://phemex.com/news/article/limit-break-exploit-on-ethereum-drains-17m-in-nfts-via-payment-processor-v2-flaw-97828","name":"Limit Break Ethereum Exploit: $1.7M in NFTs Stolen — Phemex News","type":"news_article","archive_url":"https://web.archive.org/web/20260926045818/https://phemex.com/news/article/limit-break-exploit-on-ethereum-drains-17m-in-nfts-via-payment-processor-v2-flaw-97828","credibility":2,"archive_timestamp":"2026-09-26T04:58:18+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-09-25T23:03:55.421232+00:00","updated_at":"2026-09-26T20:00:57.824136+00:00"}}