News Report Technology
September 25, 2026

Magic Eden Suspected Of NFT Security Vulnerability As White Hat Moves 3,832 NFTs

In Brief

Magic Eden faces a suspected NFT security vulnerability after a white hat moved 3,832 NFTs, with Yuga Labs confirming a rescue operation to return assets.

Magic Eden Suspected Of NFT Security Vulnerability As White Hat Moves 3,832 NFTs

NFT marketplace Magic Eden is suspected of a security vulnerability after 3,832 NFTs were moved from hundreds of wallets in a wave of unusual transactions on September 25. The activity was later attributed to a white-hat rescue operation led by Quit, Yuga Labs’ vice president of blockchain, though Magic Eden has not confirmed the nature or scale of the incident.

The activity was first flagged by NFT trader Cirrus, who observed a single wallet draining 3,832 NFTs from hundreds of different wallets. The transfers appeared onchain as sales originating from Magic Eden, with thousands of NFTs effectively sold for 0 ETH — a pattern Cirrus said could indicate the marketplace’s contract had been exploited. The trader advised users who had previously interacted with Magic Eden to revoke their NFT approvals and permissions, particularly if they held valuable assets.

The wallet involved appeared to be funded from an address possibly linked to pseudonymous X user Quit, raising the possibility of a white-hat operation. That was confirmed shortly afterward: Yuga Labs CEO Michael Figge stated that a vulnerability had been discovered a few hours earlier and that Quit was carrying out a white-hat rescue of the affected assets. In his original post, Figge wrote that “Quit is in the pocket rn white hat rescue of affected assets, everything safu, more info soon.”

Quit later clarified that the operation is indeed a white hat, and that the rescued NFTs are secured at the address 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33. 

According to Quit, the assets are safe and will be returned to their original owners once they are no longer considered at risk.

Despite these assurances, no confirmation from Magic Eden has established that the address belongs to an authorized white hat or that the transactions form part of a coordinated recovery effort. At the time of writing, the marketplace had not released an official statement confirming an exploit, and the cause and full scope of the issue remain undisclosed.

Context: A Wind-Down EVM Marketplace

The unusual Ethereum NFT activity comes months after Magic Eden narrowed its marketplace operations. The platform ended support for its Bitcoin and EVM-based NFT marketplaces earlier this year, retaining its Solana marketplace. Magic Eden’s own support documentation states that EVM marketplace support ended on March 9, with listings, bids and offers held offchain and ceasing to be visible or actionable after the shutdown.

The company continues to support its Solana marketplace, and its current products include Packs, which can contain NFTs from Ethereum collections and, once revealed, traded on the marketplace. Magic Eden has yet to say whether the Sept. 25 activity affected any of those services or involved contracts associated with its discontinued EVM marketplace — a question likely to remain central as more information emerges about the suspected vulnerability.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

More articles
Alisa Davidson
Alisa Davidson

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

Hot Stories
Join Our Newsletter.
Latest News

Shufti, Jumio, Sumsub, And Beyond: Top 6 Identity Verification And Compliance Platforms To Know In 2026

Shufti, Sumsub, Incode, Veriff, Persona and Jumio compared on compliance lifecycle coverage, pricing transparency and fraud detection ...

Know More

2026 AI Market Claims Vs SEC Fillings: Linkmate Analysis

Is the AI market really all just PR talk or there's a deeper math going on in ...

Know More
Read More
Read more
The 2026 Crackdown: How Regulators Extended AML Reporting And Transaction Controls To Individual Crypto Users
Opinion Technology
The 2026 Crackdown: How Regulators Extended AML Reporting And Transaction Controls To Individual Crypto Users
September 25, 2026
Bitget Confirms $351.6M Hot Wallet Breach, Points To North Korea-Linked Hackers
News Report Technology
Bitget Confirms $351.6M Hot Wallet Breach, Points To North Korea-Linked Hackers
September 25, 2026
BlackRock-Designed Portfolio Strategies Come Onchain Through Ondo’s New Tokenized Products
News Report Technology
BlackRock-Designed Portfolio Strategies Come Onchain Through Ondo’s New Tokenized Products
September 24, 2026
Duelbits Hit By Suspected Private Key Compromise As Losses Approach $6M
News Report Technology
Duelbits Hit By Suspected Private Key Compromise As Losses Approach $6M
September 24, 2026