• Wallet security service Revoke.cash warned on 25 September that a vulnerability in Limit Break’s Payment Processor V2 still affects wallets that authorised the contract to move their .
  • A security researcher known as 0xQuit used it to move NFTs out of approved wallets as zero-ETH sales, describing it as a whitehat rescue. Decrypt now puts that rescue at more than 23,000 NFTs, far above the 3,832 reported when the warning first circulated.
  • Magic Eden closed its Ethereum marketplace on 9 March 2026 and has since warned users directly. The permission users granted lives on the and was never cancelled by that closure.

Somewhere in the wallets of several thousand people is a permission slip they signed, possibly years ago, for a marketplace that no longer exists. It still works. That is the whole story, and the count of affected items has climbed steadily since the first warnings went out.

If you ever listed an NFT for sale on a marketplace, on Ethereum, Solana, Polygon or anywhere else, you almost certainly gave that site standing permission to move those items out of your wallet. That permission does not expire, it does not switch off when the company shuts down, and it does not care whether you still use the site. It sits there until you go and cancel it yourself.

So the practical question this story asks you isn’t “was I a Magic Eden user”. It’s “what have I left switched on across every platform I’ve ever touched, and would I even know”.

What an approval actually is

Start with how buying and selling an NFT works, because the mechanics explain everything else.

Your NFT lives on the blockchain, recorded against your wallet address. When you list it for sale, the marketplace needs to be able to hand it over the instant a buyer pays. It cannot wake you up at 3am to sign something. So instead of moving the item to the marketplace, you grant the marketplace’s permission to move it on your behalf whenever the conditions of a sale are met.

That permission is called an approval. You will have clicked through one without much thought: a wallet pop-up asking you to approve a collection, confirm a transaction, and pay a small fee. It is a normal and necessary part of trading.

The thing worth understanding is the scope. Many approvals are not for one item. An “operator approval” hands a contract the right to move every NFT you hold in a given collection, for as long as the approval stands. Some approvals work the same way with unlimited amounts. You are not lending out a single object. You are handing over a key and trusting whoever holds it to use it only as intended.

Why closing the marketplace changed nothing

Iron gate with a padlock securing a closed entrance in Portland, Oregon.
A padlocked gate blocks the entrance, but the lock only works if someone actually turned the key: token approvals stay open until you revoke them, whatever happened to the marketplace behind them. Photo by Kevin Bidwell on Pexels.

Magic Eden ended support for its EVM marketplace on 9 March 2026, according to CryptoSlate’s write-up of the Revoke.cash notice. Listings and offers on the site were held off-chain, meaning they existed on the company’s own servers rather than on Ethereum, so they simply stopped being visible or actionable when the marketplace went dark.

The approval was never on the company’s servers. It was written to the blockchain by you, and it points at a smart contract rather than at a website. Turning off the front end does not reach it. Nobody at the company has a button that revokes it on your behalf, which is a straightforward consequence of the decentralisation that the same industry spends a lot of time praising.

The contract in question is Limit Break’s Payment Processor V2, a piece of infrastructure used by marketplaces to settle NFT trades while enforcing creator royalties. Revoke.cash says a vulnerability in that contract means anyone who finds it can trigger transfers from wallets that still carry the approval. It does not require your , your device or a phishing link. The permission is already there.

What the researcher did, and what it does and doesn’t mean

0xQuit used the vulnerability to move NFTs out of approved wallets, structuring the transfers as sales for zero ETH. He has said the assets are being held in a custody wallet until it is safe to return them, and described the exercise as a whitehat rescue: a security researcher exploiting a flaw in order to get valuables out of reach before someone worse does.

The scale of that rescue has grown considerably since the first warnings. Early reporting put it at 3,832 NFTs. Decrypt now reports more than 23,000, roughly six times the original count, and says Magic Eden has itself warned that old Ethereum listings are exposed to the flaw. The company’s own warning is the first direct word from any of the named parties, and it removes a large part of the uncertainty we flagged when this was circulating only through third-party security notices.

The other thing that has changed is who was doing the exploiting. The Defiant reports that attackers, not only the whitehat, used the legacy Magic Eden approvals, and that the activity spanned Ethereum and ApeChain rather than Ethereum alone. Revoke.cash had originally said it could not establish how many NFTs, if any, malicious actors had taken. That question now has an answer in principle, even if the total does not.

A rescue is also not the same as being safe. If your NFTs are now sitting in someone else’s custody wallet awaiting return, your approval is still live. The flaw is still there. The only thing that has changed is that the items a whitehat could reach have been moved, and on current reporting they were not the only items being moved.

There is a longer-running discomfort in this pattern. Whitehat rescues have become a familiar feature of crypto incidents, and they work, but they ask a lot of ordinary holders: trust an anonymous account that has just taken your property, on the basis that the alternative was worse. Usually that trust is repaid. It is a strange system to have to rely on.

How to check what you’ve left switched on

Revocation is a transaction like any other. You connect your wallet to an approval checker, it reads the blockchain for permissions attached to your address, and you cancel the ones you no longer want. Revoke.cash is the best-known of these tools and is the service that issued this warning; Etherscan has a token approvals page that does the same job. The process costs a network fee for each revocation, which on Ethereum can be a few pounds and on cheaper networks is pennies.

The sensible habit is to work through every marketplace, bridge, game and app you have connected a wallet to and cancel anything you are not actively using. That now plainly includes ApeChain as well as Ethereum for anyone who listed through Magic Eden. Pay particular attention to platforms that have shut down, rebranded or been acquired, because those are the ones nobody is maintaining. Expect this to take longer than you think, and expect to find approvals you have no memory of granting.

One caution before you connect anything. Fake revocation sites are a well-established scam, promoted through search ads and replies on social media, and they are aimed squarely at people who have just read a story like this one and are feeling anxious. Type the address yourself, check it carefully, and treat any “revoke your approvals” link sent to you as hostile by default. The same logic that keeps you safe elsewhere in self-custody applies here: the urgency is the attack.

The wider problem this points at

Platforms close. Companies pivot, run out of money, or decide a product line is not worth maintaining. What they leave behind is a layer of live permissions across hundreds of thousands of wallets, pointing at contracts that may no longer have anyone auditing them.

Nobody maintains a register of that. There is no process by which a marketplace winding down is required to prompt its users to revoke, and no obvious party with an incentive to do it. The closest thing the ecosystem has is third-party security services publishing warnings after the fact, which is what happened here, with the platform’s own warning arriving later.

That is a structural gap rather than a Magic Eden failing, and it will produce more stories like this one as the platforms of the last NFT cycle finish shutting down.

What to watch

Magic Eden has now warned users directly, so the open questions are narrower and more practical. A published list of affected contract addresses, a count of what malicious actors actually took across Ethereum and ApeChain, and a stated process for returning the 23,000-odd rescued NFTs would let affected owners act instead of guess. None of those exist yet.

And when you next see a marketplace or app announce it is closing, note whether the announcement tells users to revoke their approvals. Most do not. Coverage of shutdowns in NFTs tends to focus on the listings that disappear rather than the permissions that stay behind, and the permissions are the part that can still cost you something.

Update, 26 September 2026: Decrypt now reports the whitehat rescue covered more than 23,000 NFTs rather than the 3,832 reported when the warning first circulated, and that Magic Eden has warned users directly about the exposed legacy listings. The Defiant reports that malicious actors, not only the whitehat researcher, exploited the same approvals, across ApeChain as well as Ethereum. The article has been updated throughout, including the summary and the closing section.