Skip to main content
AVOID.NET

Audit log

Every state-changing event for Limit Break Payment Processor V2 — Magic Eden NFT Exploit: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-25 23:04:08Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 450,495,076
    sig
    2qdALnGZ4iJR…ez2RJTHqexplorer ↗
    hash
    2H8QEGoXp3f9…1c8rnymwsha256 → base58
    verifying row…full verify ↗
    canonical bytes (14335 B) ▸
    {"actor":"system:backfill","investigation_id":"d448fc27-cd32-4bb0-90a4-400dbf1b1ce7","kind":"publish","page_slug":"limit-break-payment-processor-v2-magic-eden-nft-exploit","published_at":"2026-09-25T23:04:08.486Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Limit Break Payment Processor V2 — Magic Eden NFT Exploit","sections":[{"content":"A vulnerability in Limit Break's Payment Processor V2 smart contract allowed an attacker to act as the holder of any NFT that had been approved to the contract and take it for zero payment. The contract had been used by Magic Eden to settle trades on its Ethereum, Polygon, and Base marketplaces beginning in 2024. The flaw could also reportedly be run in reverse to draw WETH out of wallets that had granted the contract a standing token approval, without a new signature from the victim. The first known attack occurred on approximately September 24, 2026, when an attacker stole more than 300 NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives, and sold several into marketplace bids for effectively no cost to the attacker.","heading":"Nature of the Exploit","severity":"critical","sources":[{"credibility":2,"name":"Magic Eden interim update on X regarding the Payment Processor V2 exploit","type":"official","url":"https://x.com/MagicEden/status/2103435423389241569"},{"credibility":2,"name":"Magic Eden legacy approvals leave $5.7 million in NFTs exposed to exploit before rescue — The Block","type":"news_article","url":"https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874"},{"credibility":2,"name":"Magic Eden and Limit Break exploit: WETH and NFTs drained — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/magic-eden-limit-break-exploit-weth-nfts-revoke-approvals/"}]},{"content":"According to reporting corroborated by whitehat researcher 0xQuit (VP of Blockchain at Yuga Labs), Limit Break was able to pause Payment Processor V3 on most chains because that version included a pause mechanism, but Payment Processor V2 — the version Magic Eden had used on Ethereum, Polygon, and Base — could not be paused or upgraded. This means any wallet that granted an approval to the V2 contract, generally while listing or bidding on NFTs on Magic Eden's EVM marketplace between roughly February and October 2024, remains permanently exposed unless the wallet owner manually revokes the approval. Magic Eden and third-party tools such as Revoke.cash have urged affected users to check and revoke approvals on Ethereum, Polygon, and Base.","heading":"No Pause or Upgrade Mechanism — Permanent Exposure","severity":"critical","sources":[{"credibility":2,"name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"community_report","url":"https://revoke.cash/exploits/magic-eden?chainId=1"},{"credibility":2,"name":"Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit — Decrypt","type":"news_article","url":"https://decrypt.co/379342/magic-eden-old-ethereum-nft-listings-exposed-exploit"}]},{"content":"Reported figures vary somewhat by outlet and by the time each snapshot was taken, consistent with an incident that was still unfolding as of the last reporting reviewed. The Block reported that confirmed losses across multiple chains totaled at least $2.8 million as of September 25, 2026, 12:00 UTC, with attacks still ongoing at that time. CryptoTicker reported chain-specific figures on Ethereum of 530.7 WETH drained from 911 wallets (approximately $1.43 million at the time), plus 8,380 USDC and roughly 549,000 WILD tokens, and on ApeChain, 7,680 WAPE taken from 19 wallets. Separately, 0xQuit and multiple outlets reported that approximately 660 WETH (variously valued between roughly $1.6 million and $1.7 million depending on the price snapshot used) could not be recovered by the whitehat team before attackers drained it. These figures should be treated as preliminary and potentially subject to revision as the incident is fully reconciled.","heading":"Financial Losses","severity":"high","sources":[{"credibility":2,"name":"Magic Eden legacy approvals leave $5.7 million in NFTs exposed to exploit before rescue — The Block","type":"news_article","url":"https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874"},{"credibility":2,"name":"Magic Eden and Limit Break exploit: WETH and NFTs drained — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/magic-eden-limit-break-exploit-weth-nfts-revoke-approvals/"},{"credibility":2,"name":"How 0xQuit Rescued $5.7M in NFTs — Gizmo Times","type":"news_article","url":"https://www.gizmotimes.com/blockchain/nft/0xquit-rescues-nfts-limit-break-exploit/51465"}]},{"content":"Security researcher 0xQuit, identified in reporting as VP of Blockchain at Yuga Labs, discovered the exploit pattern, contacted Limit Break, and led a defensive operation that used the same underlying flaw to move at-risk NFTs into a rescue wallet before attackers could reach them, rather than to profit from the vulnerability. In total, the operation is reported to have protected 23,155 NFTs valued at more than $5.7 million across Ethereum and ApeChain. 0xQuit stated that the NFTs held in the rescue wallet were safe and would be returned to their owners once they were no longer exposed. Despite this response, the team was not able to prevent the theft of roughly 660 WETH before securing it.","heading":"Whitehat Rescue Operation","severity":"medium","sources":[{"credibility":2,"name":"How 0xQuit Rescued $5.7M in NFTs — Gizmo Times","type":"news_article","url":"https://www.gizmotimes.com/blockchain/nft/0xquit-rescues-nfts-limit-break-exploit/51465"},{"credibility":2,"name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"community_report","url":"https://revoke.cash/exploits/magic-eden?chainId=1"}]},{"content":"Magic Eden stated on X that it stopped using Payment Processor V2 in October 2024 and shut down its EVM marketplace entirely in Q1 2026, and that no live Magic Eden listings were affected by this exploit. The company said the risk was confined to legacy, unrevoked approvals from NFTs listed on its EVM marketplace between approximately February and October 2024, and advised affected users to revoke Payment Processor V2 approvals on Ethereum, Polygon, and Base. The incident illustrates that a marketplace's decision to discontinue a smart contract does not remove the contract from the blockchain or void approvals users previously granted to it — a risk that persisted for roughly two years after Magic Eden stopped using the affected version.","heading":"Magic Eden's Discontinuation and Public Response","severity":"medium","sources":[{"credibility":2,"name":"Magic Eden interim update on X regarding the Payment Processor V2 exploit","type":"official","url":"https://x.com/MagicEden/status/2103435423389241569"},{"credibility":2,"name":"Magic Eden Clarifies the Impact of the NFT Vulnerability and Advises Users to Revoke Contract Approvals — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/magic-eden-clarifies-nft-vulnerability-impact-advises-users-to-revoke-contract-approvals"}]},{"content":"Because Payment Processor V2 cannot be paused or upgraded, any wallet that granted it an approval and has not since revoked that approval remains at risk of having NFTs or approved tokens such as WETH taken without further authorization, independent of whether the owner still uses Magic Eden. Revoke.cash and multiple news outlets published guidance directing users to check exposure and revoke approvals on Ethereum, Polygon, Base, and, for a related Payment Processor V3 flaw, other chains including Arbitrum and ApeChain. As of the most recent reporting reviewed, this exposure had not been resolved for all affected wallets and attacks were described as ongoing.","heading":"Ongoing Risk for Wallets with Legacy Approvals","severity":"high","sources":[{"credibility":2,"name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"community_report","url":"https://revoke.cash/exploits/magic-eden?chainId=1"},{"credibility":2,"name":"Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit — Decrypt","type":"news_article","url":"https://decrypt.co/379342/magic-eden-old-ethereum-nft-listings-exposed-exploit"}]}],"sources_used":[{"credibility":2,"name":"Magic Eden interim update on X regarding the Payment Processor V2 exploit","type":"official","url":"https://x.com/MagicEden/status/2103435423389241569"},{"credibility":2,"name":"Magic Eden legacy approvals leave $5.7 million in NFTs exposed to exploit before rescue — The Block","type":"news_article","url":"https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874"},{"credibility":2,"name":"Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit — Decrypt","type":"news_article","url":"https://decrypt.co/379342/magic-eden-old-ethereum-nft-listings-exposed-exploit"},{"credibility":2,"name":"2026 Magic Eden / Limit Break Hack: Check If You're Affected — Revoke.cash","type":"community_report","url":"https://revoke.cash/exploits/magic-eden?chainId=1"},{"credibility":2,"name":"Magic Eden and Limit Break exploit: WETH and NFTs drained — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/magic-eden-limit-break-exploit-weth-nfts-revoke-approvals/"},{"credibility":2,"name":"How 0xQuit Rescued $5.7M in NFTs — Gizmo Times","type":"news_article","url":"https://www.gizmotimes.com/blockchain/nft/0xquit-rescues-nfts-limit-break-exploit/51465"},{"credibility":2,"name":"Magic Eden Clarifies the Impact of the NFT Vulnerability and Advises Users to Revoke Contract Approvals — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/magic-eden-clarifies-nft-vulnerability-impact-advises-users-to-revoke-contract-approvals"},{"credibility":2,"name":"Magic Eden responds to vulnerability issue — TechFlow","type":"news_article","url":"https://www.techflowpost.com/en-US/newsletter/137771"},{"credibility":2,"name":"Magic Eden Payment Processor V2 Vulnerability Alert — Phemex News","type":"news_article","url":"https://phemex.com/news/article/magic-eden-warns-of-payment-processor-v2-vulnerability-affecting-early-2024-evm-listings-97842"},{"credibility":2,"name":"Magic Eden NFT Exploit Puts 3,832 NFTs at Risk — NFT Playgrounds","type":"news_article","url":"https://www.nftplaygrounds.com/post/magic-eden-nft-exploit-puts-3-832-nfts-at-risk"},{"credibility":2,"name":"Whitehats rescue $5.7 million in NFTs after Limit Break Payment Processor exploit — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/whitehats-rescue-5-7-million-in-nfts-after-limit-break-payment-processor-exploit/"},{"credibility":2,"name":"Limit Break Ethereum Exploit: $1.7M in NFTs Stolen — Phemex News","type":"news_article","url":"https://phemex.com/news/article/limit-break-exploit-on-ethereum-drains-17m-in-nfts-via-payment-processor-v2-flaw-97828"}],"summary":"Payment Processor V2, an NFT-trading smart contract built by Limit Break and formerly used by Magic Eden's Ethereum marketplace, was actively exploited beginning around September 24, 2026. Attackers used standing 2024-era wallet approvals to drain NFTs and WETH from victims for zero payment; a whitehat operation led by Yuga Labs' 0xQuit rescued roughly $5.7 million in NFTs, but confirmed losses reached at least $2.8 million across several chains and the underlying contract has no pause or upgrade mechanism, leaving any wallet that approved it in 2024 permanently exposed unless it revokes the approval.","timeline":[{"date":"2024-02","event":"Approximate start of the period during which NFTs listed or bid on via Magic Eden's EVM marketplace generated approvals to the Limit Break Payment Processor V2 contract that would later be exploitable.","source":"The Block","source_url":"https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874"},{"date":"2024-10","event":"Magic Eden stopped using Payment Processor V2 to settle trades on its EVM marketplace.","source":"Magic Eden statement on X / The Block","source_url":"https://x.com/MagicEden/status/2103435423389241569"},{"date":"2026-01","date_evidence":"Magic Eden ... ceased its EVM marketplace altogether in Q1 2026","event":"Magic Eden ceased its EVM marketplace altogether (reported as occurring in Q1 2026); exact month not specified by sources.","source":"The Block","source_url":"https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874"},{"date":"2026-09-24","date_evidence":"The first known attack happened on 24 September 2026, when an attacker stole over 300 NFTs on Ethereum and sold them into marketplace bids.","event":"First known attack: an attacker exploited Payment Processor V2 to steal over 300 NFTs, including 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives, for zero payment.","source":"Web search aggregation of contemporaneous reporting","source_url":"https://www.gizmotimes.com/blockchain/nft/0xquit-rescues-nfts-limit-break-exploit/51465"},{"date":"2026-09","date_evidence":"As of 25 September 12:00 UTC the stolen assets were worth at least $2.8M, and attacks were still ongoing.","date_original":"2026-09-25","event":"Confirmed losses reached at least $2.8 million across Ethereum, Polygon, Base, Arbitrum, and ApeChain as attacks continued; 0xQuit and collaborators conducted a whitehat rescue of 23,155 NFTs worth more than $5.7 million; Limit Break paused Payment Processor V3; approximately 660 WETH was drained before it could be secured; Magic Eden published a public update urging users to revoke approvals.","source":"The Block / Magic Eden / Gizmo Times","source_url":"https://www.theblock.co/news/web3/2026-09-25-magic-eden-legacy-approvals-leave-5-7-million-in-nfts-exposed-to-exploit-before-rescue-416874"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision cd7a796f-5d73-46d9-ad87-8d7736f9f6d9
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.