The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Magic Eden and Limit Break exploit: 530 WETH and thousands of NFTs drained, how to revoke your approvals

A bug in Limit Break's Payment Processor, the protocol behind Magic Eden's former Ethereum marketplace, has been draining NFTs and WETH since Thursday. Our blockchain analysis shows 911 affected wallets. What happened, why hardware wallets do not protect you and which two approvals to revoke now.

Open vault door with an old brass key still in the lock and scattered coins on the floor
14 min read
Share:

If you listed an NFT, placed an offer or accepted one on Magic Eden's former Ethereum marketplace in 2024, you need to act now. A bug in Limit Break's Payment Processor, the trading protocol behind that marketplace, has been used since Thursday to pull NFTs and Wrapped Ether (WETH) out of other people's wallets. On ApeChain, Wrapped ApeCoin (WAPE) was hit. Our own analysis of the blockchain shows 530.7 WETH gone from 911 wallets, plus thousands of NFTs, and at our last check at 12:40 UTC the drain was still running.

Protecting yourself takes minutes: you revoke the approvals for two contracts. Cancelling a listing is not enough. And a hardware wallet does not protect you here. We explain why in detail below, because it is being misrepresented in many replies on X right now.

Magic Eden and Limit Break: the two approvals you need to revoke now

Two contracts are affected. Quit, VP of Blockchain at Yuga Labs, named them publicly on Friday morning:

  • Payment Processor V2 on Ethereum: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834
  • Payment Processor V3 on ApeChain: 0x9a1D00000000fC540e2000560054812452eB5366

Magic Eden also names Polygon and Base, because the marketplace used Payment Processor V2 there as well. Check your wallet on all four networks. In your wallet the contract usually shows up as "Limit Break: Payment Processor". That is the name you saw in the signature window back then, when you placed or accepted an offer.

What happened in the Limit Break exploit: the timeline

We built the timeline from three sources: posts by the people involved on X, the incident page on Revoke.cash and our own analysis of the events that the Payment Processor leaves on the blockchain. All times are UTC.

  • Thursday, September 24, 13:08: The first attack. A single address pulls 305 NFTs out of a single wallet in three transactions, each as a "sale" at a price of zero. Quit lists 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives, exactly 305. Nobody notices for twelve hours.
  • Friday, September 25, around 01:00: Quit comes across the incident and realises that a large number of other wallets can be reached through the same bug. He contacts Limit Break, which pauses Payment Processor V3. V2 on Ethereum cannot be paused.
  • 05:46: The rescue begins. Quit and helpers pull at-risk NFTs out through the bug themselves and park them at 0x71cF3f5724bD2B72Ef6464992aCd26216De7fe33.
  • 06:31: NFT trader Cirrus raises the alarm because one address is "buying" thousands of NFTs for 0 ETH. At 06:47 Quit confirms that it is his rescue.
  • 07:06: The rescue starts on ApeChain as well.
  • 08:09: Quit publicly calls on users to revoke their approvals.
  • 08:25: The WETH drain begins. The first transaction alone takes 281.66 WETH from 25 wallets. By 09:00, 522.5 WETH are gone.
  • 08:51 and 09:10: Other tokens are hit too: 8,380 USDC from 62 wallets and around 549,000 WILD from eleven wallets.
  • 09:11: Revoke.cash publishes a dedicated checker page for the incident.
  • 09:54: On ApeChain, 7,680 WAPE disappear from 19 wallets in a single transaction.
  • 10:11: The last transfer to the rescue address. At 10:19 all activity on the ApeChain contract stops.
  • From 09:27 until at least 12:22: Other addresses keep pulling NFTs at zero price, 7,870 transfers from 1,786 wallets in total. The latest WETH drain in our data is at 12:19.
  • 12:22 to 12:40: Our follow-up check shows another 2,292 NFT transfers at zero price and another 0.55 WETH from five purchases. The attack is not over.
Bar chart: NFTs pulled at zero price per hour on Sept 24 and 25, 2026, rescue address versus other addresses
Until 10:00 UTC the rescue address did most of the pulling, after that other addresses took over.

The chart shows the turning point. Until late morning almost every transfer comes from the rescue address. After that, others take over. Who is behind those addresses cannot be read from the blockchain. They could be further helpers or copycats who rebuilt the exploit. For you it makes no difference: as long as the approval stands, anyone can use it.

Quit puts the night's result at 23,155 rescued NFTs worth more than $5.7 million. Our data shows 16,117 transfers to the rescue address on Ethereum and 9,795 on ApeChain. The figures do not match one to one, because one event is not always exactly one NFT; multi-edition tokens can carry several copies. The order of magnitude is right.

Why WETH and WAPE were drained

Many people are asking this, and the answer explains the whole attack. No contract can pull plain Ether out of your wallet. A contract can only move tokens you have given it permission for, an approval in crypto jargon. NFT marketplaces use two kinds.

The NFT approval. Listing an NFT lets the marketplace contract transfer it on sale, usually for the whole collection ("approved for all"). The zero-price NFT transfers went out through this approval.

The token approval. An offer on an NFT is not paid in Ether but in wrapped Ethereum, WETH. It is a token pegged one to one to Ether that can be approved like any other token. So that an offer can be settled automatically later, you allow the Payment Processor to spend your WETH, as a rule in unlimited amounts and with no expiry. On ApeChain it works the same way with WAPE, the wrapped form of ApeCoin.

That is why these two tokens were hit. The USDC, WILD and APE drains in our data show, however, that any token you ever approved for the Payment Processor is exposed.

Three-step diagram: old WETH approval, dummy NFTs as bait, drain through Payment Processor
How the WETH drain worked in a single transaction.

A single transaction shows the trick step by step. The attackers deploy a fresh contract that mints 25 worthless dummy NFTs and lists them for sale. They then have the Payment Processor "buy" these dummy NFTs on behalf of 25 other wallets. Payment comes out of the victims' WETH, via the old approval, without any of them signing anything. The largest single item in this transaction: 29.39 WETH from one wallet. How exactly the contract is made to act on someone else's behalf has not been disclosed by Limit Break or Quit so far.

Important if you still hold or swap WETH: the approval covers every WETH that lands in your wallet, including future balances. If you wrap Ether into WETH or receive WETH in a swap while the approval stands, you put it straight within the attackers' reach. Revoke first, then swap.

"But I had a hardware wallet": why a Ledger does not protect you

Under the warnings on X, some are mocking victims: anyone using a hardware wallet is safe, they say. That is not true here, and many of those affected had one. An acquaintance of our newsroom lost 5.94 WETH despite using a Ledger.

The reason lies in where an approval is stored. A hardware wallet protects your private key. It ensures that nobody can sign in your name without the device. But you already signed the approval, back then, perhaps two years ago, with that very device. Since then it has sat in the token contract on the blockchain: "The Payment Processor may move WETH from this address." When the Payment Processor now pulls WETH, nobody asks your device. The Ledger stays in the drawer, and the money leaves anyway.

A hardware wallet protects against stolen keys, not against rights you granted yourself. Keeping the two apart helps you focus on what actually works in incidents like this. For an overview of devices, see our hardware wallet comparison; you still have to manage your approvals yourself.

Bar chart: WETH losses per wallet by size, 911 wallets, 530.7 WETH
Half of the wallets lost less than 0.1 WETH, ten wallets lost 196 WETH between them.

How big is the damage from the Magic Eden exploit?

Our count on Ethereum comes to 530.7 WETH from 911 wallets. At an Ether price of $2,702.88 (CoinGecko, September 25, 2026, 12:25 UTC) that is about $1.43 million. Most victims lost small amounts: half the wallets lost less than 0.1 WETH. Ten wallets, by contrast, each lost more than 10 WETH, 196 WETH between them.

Quit speaks of 660 WETH he could no longer rescue, about $1.7 million. The gap to our figure is probably explained by the fact that we only analysed Ethereum; Polygon and Base are missing. On top of that, our data shows 8,380 USDC, about 549,000 WILD (roughly $7,200), 12.9 APE on Ethereum and 7,680 WAPE on ApeChain.

The NFT picture is harder to add up. What sits at the rescue address is due to be returned. What has gone to other addresses since late morning, 7,870 transfers from 1,786 wallets, remains an open question for now.

Quit wrote on Friday morning that he had worked through the night to save around $6 million worth of NFTs, and that all he could think about was the $1.7 million in WETH he was not fast enough for. Since then, victims who lost WETH have been replying under his posts, some of them by their own account having revoked an hour too late.

Who is 0xQuit, the overnight rescuer?

Quit is VP of Blockchain at Yuga Labs, the company behind Bored Ape Yacht Club, CryptoPunks and Otherside. On X he describes himself as a Solidity developer and auditor, and he founded the NFT tool oSnipe. He regularly warns about vulnerabilities on X and, when in doubt, steps in himself before others can exploit them.

It is not his first rescue this year. In June, during a bug in Flooring Protocol, he pulled 68 NFTs worth more than $500,000 out of vulnerable pools, including 29 Bored Apes and two CryptoPunks, and held them for their owners. The approach was the same both times: whoever knows the bug pulls the assets out first, before someone with bad intentions does, and returns them once the danger has passed.

What Magic Eden and Limit Break say

Magic Eden stresses the distinction: the marketplace itself was not attacked. Co-founder and CEO Jack Lu wrote on X that the incident concerns Limit Break's trading protocol and contracts, which Magic Eden stopped using two years ago. According to Magic Eden, it used Payment Processor V2 from February to October 2024 and shut down its EVM marketplace entirely in the first quarter of 2026. Current listings are not affected, and the company says it is talking to Limit Break about further steps.

Limit Break itself had not issued a statement of its own by our deadline. All that is known is what Quit reports: that the team quickly paused V3 on ApeChain. Several NFT projects on ApeChain acted on their own. The team behind Dengs, for example, says it temporarily froze all Deng NFTs, and ApeDroidz reported that some of its collection is among the rescued assets.

If you want to review the marketplaces where NFTs trade today, you will find the comparison below. More on Magic Eden's retreat from the Ethereum business is in our analysis of the Magic Eden shutdown.

Revoke approvals: how to protect your wallet step by step

  1. Open Revoke.cash and enter your address or connect your wallet. Revoke.cash lists the incident on its own checker page, where you can test your address directly.
  2. Go through network by network: Ethereum, ApeChain, Polygon and Base.
  3. Revoke every approval for the Payment Processor, that is 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 on Ethereum, Polygon and Base and 0x9a1D00000000fC540e2000560054812452eB5366 on ApeChain. This covers NFT approvals ("approved for all") as well as token approvals for WETH, WAPE, USDC or APE.
  4. Each revoke transaction costs a small fee and has to be signed with your wallet, on the device itself if you use a hardware wallet.
  5. Only then touch WETH again. No swap into WETH and no wrapping of Ether while the approval stands.
Screenshot der Revoke.cash-Seite zum Magic Eden / Limit Break Hack mit Adressprüfung
Revoke.cash führt den Vorfall als eigene Exploit-Seite, mit Prüffeld für die eigene Adresse. Screenshot vom 25.09.2026.

What does not help: cancelling listings or bumping the so-called master nonce. Revoke.cash explicitly points out that neither does anything against this bug. And revoking does not bring back what has already gone. It only stops more from leaving.

According to Quit, you will only get rescued NFTs back once your approval has been revoked, otherwise the NFT would be exposed again straight away. There is no official return process yet. Expect scammers to exploit exactly this situation over the coming days: direct messages offering "recovery", fake return pages, requests to sign a message. Do not sign anything someone sends you, and wait for announcements from the known accounts.

What the exploit means for the NFT market

The real lesson of the day is an uncomfortable one: approvals do not expire. Magic Eden stopped using Payment Processor V2 almost two years ago and closed the marketplace this spring. The rights that thousands of users had granted to that contract stayed in place regardless, and the contract itself kept running, with no emergency brake. A platform can close; its contracts on the blockchain do not close with it.

Add to that the industry habit of granting unlimited approvals, so that users do not have to pay for a second transaction with every offer. It saves a few cents and turns every forgotten approval into an open account.

The incident falls in a striking week. On Thursday evening Bitget reported an outflow of about $352 million from hot wallets, the largest hack of the year; what Bitget customers should check now is in our report. The same evening, Quit also counted an attack on Payy worth $1.8 million. The tools are getting better on both sides. Research published this year shows that AI agents can now find and exploit smart contract vulnerabilities at scale, particularly in old contracts that nobody maintains any more. Whether AI played a role in this attack is not known. What is clear: searching for forgotten bugs is getting cheaper, and this night's rescue hinged on one person who happened to be awake.

How we analysed the blockchain data on the Limit Break exploit

We read every trade event that Payment Processor V2 emitted on Ethereum between September 23, 2026, 12:00 UTC and September 25, 2026, 12:22 UTC, blocks 26,040,040 to 26,054,436, queried through public Ethereum nodes. That comes to 25,299 events of the AcceptOffer and BuyListing types. The positive control: for the same block range, three independent nodes returned the same count. On ApeChain we read Payment Processor V3 from September 24 in the same way, 10,041 events.

We count a sale at a price below 0.001 tokens as an NFT drain. A token drain is a purchase in which the victim's wallet pays as the buyer. We checked the mechanism against individual transactions, such as the one with the 281.66 WETH. One cross-check with an outside source: our count for the first attack on September 24 comes to 305 NFTs, the same figure Quit gives.

What the figures cannot do: Polygon and Base are not included. Who is behind the individual addresses, helper or attacker, cannot be read from the data. And one event is not always exactly one NFT. Dollar values are based on prices as of September 25, 2026, 12:25 UTC.

Magic Eden, WETH and old approvals: key takeaways

If you traded on Magic Eden, Otherside or an ApeChain marketplace in 2024, revoke the approvals for the Payment Processor today, on Ethereum, ApeChain, Polygon and Base. Do not wrap Ether into WETH while the approval stands. A hardware wallet protects your key, not rights you have already granted. And beyond today: go through your approvals regularly, say once a quarter, and revoke them immediately when a platform shuts down. Keep valuable assets in a wallet you do not trade from and never approve anything with.

(As of September 25, 2026, 12:45 UTC. This article is not investment advice. The situation is still developing; check official statements from Limit Break and Magic Eden before you act.)

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

Related articles

More from CryptoTicker