NewsCryptoMagic Eden Suspected of NFT Security Vulnerability as White Hat Moves 3,832 NFTs

Magic Eden Suspected of NFT Security Vulnerability as White Hat Moves 3,832 NFTs

Author: Metaverse Post·

Key Takeaways

  • •A single wallet moved 3,832 NFTs from hundreds of different wallets on September 25 in transfers that appeared onchain as Magic Eden sales priced at 0 ETH, meaning buyers paid nothing and sellers received no proceeds.
  • •Yuga Labs CEO Michael Figge stated that a vulnerability was discovered a few hours earlier and that Quit, Yuga Labs' vice president of blockchain, was carrying out a white-hat rescue of the affected assets.
  • •Quit confirmed the rescued NFTs are secured at the address 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 and said they will be returned to their original owners once they are no longer considered at risk.
  • •Magic has not released an official statement confirming an exploit, and neither the cause nor the full scope of the incident has been disclosed, leaving the exact transfer mechanism unclear.
  • •Earlier this year, Magic Eden ended support for its Bitcoin and EVM-based NFT marketplaces, retaining only its Solana marketplace, and has not yet said whether the September 25 activity involved contracts tied to the discontinued EVM platform.
Magic Eden Suspected of NFT Security Vulnerability as White Hat Moves 3,832 NFTs

NFT marketplace Magic Eden is suspected of a security vulnerability after 3,832 NFTs were moved from hundreds of wallets in a wave of unusual transactions on September 25. The activity was later attributed to a white-hat rescue operation led by Quit, Yuga Labs' vice president of blockchain, although Magic Eden has not confirmed the nature or scale of the incident.

The unusual transfers were first flagged by NFT trader Cirrus, who observed a single wallet draining 3,832 NFTs from hundreds of different wallets. Onchain, the transfers appeared as sales originating from Magic Eden, with thousands of NFTs effectively sold for 0 ETH — meaning the recipients paid nothing for the assets and the listed sellers received no proceeds. Cirrus said the pattern could indicate that the marketplace's contract had been exploited, and advised users who had previously interacted with Magic Eden to revoke their NFT approvals and permissions, particularly if they held valuable assets in their wallets. The breadth of the movement is part of what made the episode stand out: an issue at the marketplace level can touch hundreds of holders in a single wave rather than one wallet at a time.

No idea whats going on here but I just watched this wallet drain 3832 NFTs from 100s of different wallets May be a good idea to revoke all NFT permissions if you have any valuables in your wallet Seems to be funded from a wallet possibly linked to @0xQuit so maybe a whitehat? pic.twitter.com/semJYsjEXX

— Cirrus (@CirrusNFT) September 25, 2026

The wallet involved appeared to have been funded from an address possibly linked to pseudonymous X user Quit, raising the possibility of a white-hat operation. That was confirmed shortly afterward: Yuga Labs CEO Michael Figge stated that a vulnerability had been discovered a few hours earlier and that Quit was carrying out a white-hat rescue of the affected assets. In his original post, Figge wrote that "Quit is in the pocket rn white hat rescue of affected assets, everything safu, more info soon."

exploit discovered a few hrs ago, Quit is in the pocket rn white hat rescue of affected assets, everything safu, more info soon.

— figge (@mfigge) September 25, 2026

Quit later clarified that the operation was indeed conducted by a white hat and that the rescued NFTs were secured at the address 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33. According to Quit, the assets are safe and will be returned to their original owners once they are no longer considered to be at risk.

hey ya this is a whitehat and everything in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 is safe and will be returned once they are no longer at risk

— Quit (@0xQuit) September25, 2026

Despite these assurances, no confirmation from Magic Eden has established that the address belongs to an authorized white hat or that the transactions form part of a coordinated recovery effort. At the time of writing, the marketplace had not released an official statement confirming an exploit, and neither the cause nor the full scope of the issue has been disclosed, leaving the exact mechanism by which the NFTs were moved unclear — and leaving holders with no official accounting of what happened to their assets beyond the Yuga Labs executives' posts.

Context: A Marketplace in Wind-Down

The unusual Ethereum NFT activity comes months after Magic Eden narrowed its marketplace operations. Earlier this year, the platform ended support for its Bitcoin and EVM-based NFT marketplaces, retaining its Solana marketplace. According to Magic Eden's own support documentation, EVM marketplace support ended on March 9, at which point listings, bids, and offers held offchain ceased to be visible or actionable.

The company continues to support its Solana marketplace, and its current products include Packs, which can contain NFTs from Ethereum collections and, once revealed, can be traded on the marketplace. White-hat rescue operations of this kind are a recognized practice in the digital-asset industry, in which at-risk assets are moved into controlled wallets to protect them until an underlying vulnerability is resolved.

Magic Eden has yet to say whether the September 25 activity affected any of those services or involved contracts associated with its discontinued EVM marketplace — a question likely to remain central as more information emerges about the suspected vulnerability. Until then, the developments to watch are concrete: an official statement from Magic Eden identifying the cause and scope of the incident, and confirmation that the NFTs held at Quit's secured address have been returned to their original owners, which he said would happen once they are no longer at risk.

Source: Metaverse Post — Magic Eden Suspected Of NFT Security Vulnerability As White Hat Moves 3,832 NFTs