Whitehat hacker 0xQuit has secured thousands of NFTs on the Magic Eden EVM marketplace following the discovery of a critical smart contract bug. The vulnerability was traced back to Limit Break's Payment Processor V2, a protocol used to settle trades on EVM chains.

Advertisement

The vulnerability in Limit Break's Payment Processor V2

A technical flaw within Limit Break's Payment Processor V2 allowed for the unauthorized transfer of digital assets on the Magic Eden EVM marketplace. As the report indicates, this specific protocol was integrated by Magic Eden in 2024 to handle trade settlements across various EVM chains. The bug essentially allowed an attacker to exploit the contract to move NFTs without the necessary authorization from the owner.

The vulnerability highlights a growing concern regarding the reliance of major marketplaces on third-party settlement layers. While Magic Eden provides the user interface and marketplace functionality, the actual movement of assets depends on the security of protocols like Limit Break's Payment Processor V2. This creates a secondary layer of risk that users may not immediately realize when interacting with a platform.

0xQuit's $500,000 recovery track record

The whitehat hacker known as 0xQuit initiated a rescue operation that temporarily caused panic among the Magic Eden community. Because the rescue transfers were designed to mimic regular sales on the Magic Eden marketplace, many users initially feared their assets had been stolen by malicious actors. This confusion was only resolved when community members, including Cirrus , confirmed that the transfers were a protective measure.

This intervention follows a successful precedent set by 0xQuit in June, when the hacker recovered 68 NFTs worth more than $500,000 following the Flooring Protocol exploit.. According to the source, 0xQuit has once again demonstrated the role of whitehat hackers as a de facto security layer in the often-volatile NFT ecosystem by moving the at-risk assets into a secure wallet.

The February to October 2024 risk window

The vulnerability window for affected users spans from February to October 2024. Any NFTs listed on the Magic Eden EVM marketplace during this specific timeframe could potentially be at risk due to the Payment Processor V2 bug. As reported by the source, any listings made after this period are considered safe.

Magic Eden is currently in communication with Limit Break to explore preventative meassures, such as pausing all outgoing transfers to mitigate further exposure. While listings made after October 2024 are believed to be safe, the company is urging users who listed assets during the vulnerable period to review their accounts and take proactive steps to secure their holdings.

Missing details from the Limit Break interim statement

Significant gaps remain in the information provided by Limit Break and Magic Eden following the incident. While an interim statement has been issued, the companies have yet to release a comprehensive report detailing the full scope of the vulnerability or the specific technical cause. This lack of detail has left some community members seeking more transparency regarding the underlying protocol failure.

The community is still waiting for clarity on the exact timeline for returning the rescued NFTs to their rightful owners. furthermore, there is no confirmation yet on whether the Limit Break protocol has been fully patched to prevent a recurrence of this specific exploit, leaving some users cautious about the long-term security of the EVM marketplace.