Limit Break Payment Processor V2 — Magic Eden NFT Exploit
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2qdALn…JTHqSummary
On September 24–25, 2026, attackers exploited a critical vulnerability in Limit Break's Payment Processor V2 smart contract — formerly used by Magic Eden's now-defunct Ethereum EVM marketplace — to steal at least $2.8 million in NFTs and tokens from wallets holding legacy approvals dating to 2024. A white-hat rescue led by Yuga Labs' blockchain VP 0xQuit secured 23,155 NFTs valued at approximately $5.7 million before further damage could occur, but roughly 660 WETH (approximately $1.7 million) was not recovered in time. Because the contract has no pause or upgrade mechanism, the vulnerability remains permanently live on every chain where it is deployed.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(12 events)
1 February 2024
Magic Eden adopts Limit Break Payment Processor V2 to settle trades on its Ethereum EVM marketplace. Users begin granting approvals to the contract.
Magic Eden official statement via X1 October 2024
Magic Eden stops using Payment Processor V2. User approvals granted during the February–October 2024 period remain active on-chain.
Magic Eden official statement via X9 March 2026
Magic Eden shuts down its EVM marketplace entirely, but legacy on-chain approvals to Payment Processor V2 are not revoked on behalf of users.
Old Magic Eden NFT approvals put users at risk — CryptoSlate24 September 2026
First confirmed malicious attack: approximately 305 NFTs stolen on Ethereum including 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives.
2026 Magic Eden / Limit Break Hack — Revoke.cash25 September 2026
05:46:47 UTC — First white-hat rescue transaction executed by 0xQuit's team, moving vulnerable NFTs into custody wallet 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33.
Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes25 September 2026
06:31:42 UTC — NFT researcher Cirrus publicly identifies unusual transfers from wallet 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33, raising initial alarm.
Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes25 September 2026
06:47:59 UTC — 0xQuit publicly confirms the rescue operation is white-hat. Vulnerability mechanism publicly named, triggering copycat attacks.
Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes25 September 2026
09:06 UTC — 0xQuit publishes detailed account of rescue operation; reports 23,155 NFTs rescued worth over $5.7 million and approximately 660 WETH not recovered.
Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes25 September 2026
09:11 UTC — Revoke.cash launches dedicated incident checker for the exploit.
2026 Magic Eden / Limit Break Hack — Revoke.cash25 September 2026
10:39 UTC — Limit Break has paused Payment Processor V3 on most chains but has not issued an independent public statement as of this time.
Limit Break NFT Exploit: Yuga Labs' Quit Rescues 23,155 NFTs — CryptoTimes25 September 2026
10:44 UTC — Magic Eden publishes official interim statement confirming incident details and advising users to revoke approvals on Ethereum, Polygon, and Base via Revoke.cash.
Magic Eden official statement via X25 September 2026
Revoke.cash confirms at least $2.8 million in confirmed stolen assets as of 12:00 UTC, with attacks reportedly still ongoing across multiple chains.
2026 Magic Eden / Limit Break Hack — Revoke.cashDecision Log
- hash: 2H8QEGoXp3f9AQhgNWNRcqP8Tp5gPPtiGTGv1c8rnymw
This investigation is cryptographically anchored to the Solana blockchain (1 event). 13 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/25/2026, 11:03:55 PM
last updated: 9/26/2026, 8:00:57 PM
1 viewavoid.net — verified advice for a post-truth world