Some Ethereum wallets may still have exposed NFT transfer permissions granted to Magic Eden's payment-processing contracts months after the platform shut its Ethereum NFT market. Wallet-security service Revoke.cash warned on September 25, 2026, that Limit Break's Payment Processor V2 remained authorized by some wallets, creating a risk of unauthorized NFT transfers.
Security researcher 0xQuit subsequently moved 3,832 NFTs from wallets that still had the approval. The transactions were completed as sales for zero ETH. 0xQuit described the transfers as white-hat rescues and said the assets were being held temporarily in custodial wallets until the issue could be addressed and the NFTs returned.
Revoke.cash has not confirmed how many of the transfers were legitimate rescues. It also has not determined whether malicious actors had already moved any assets, leaving the final scale of any losses unclear.
Magic Eden's market closure did not remove on-chain approvals
Magic Eden ended support for EVM markets on March 9, 2026. Listings and bids on the platform were off-chain data, so they stopped being displayed or executed through the website after the market closed. The permissions users had previously granted to the Payment Processor, however, were separate on-chain approvals. Shutting down the market did not automatically revoke them.
As a result, wallets could remain exposed even if their owners had not traded on Magic Eden for months or had canceled earlier listings. The relevant contract may still have permission to operate on the NFTs unless that approval was revoked. Users therefore need to review their wallets' current contract approvals rather than relying only on past transaction records or the absence of listings on the website.
Ethereum and ApeChain require separate checks
Revoke.cash advised users to review and revoke Payment Processor V2 approvals on Ethereum. Users who previously approved Payment Processor V3 on ApeChain should check that permission separately.
An NFT operator approval allows a specified contract to transfer NFTs on behalf of a wallet. These permissions generally remain active after a transaction is completed unless the holder revokes them. Revoke.cash also stressed that canceling a Magic Eden listing does not remove the wallet's approval for the contract, and disconnecting a wallet from the website does not change an authorization already recorded on the blockchain.
Users can use the relevant approval-checking tools to determine whether an address is affected and revoke permissions for the applicable processing contract.
Revoking approval cannot recover transferred NFTs
Revoking an approval is intended to prevent future transfers; it cannot recover NFTs that have already been moved. The warning concerns the Payment Processor approvals described above and does not by itself confirm malicious losses on both Ethereum and ApeChain.
As of September 25, Revoke.cash had not published the technical details of the vulnerability or confirmed whether malicious actors had obtained any NFTs. The 3,832 NFTs moved by 0xQuit represent the disclosed number of rescue transfers, not a confirmed final-loss figure. For holders who still have the old approvals, the immediate verifiable step is to review the relevant contracts and revoke permissions that are no longer needed.