Whitehat moves 3,832 NFTs from hundreds of wallets after Magic Eden-linked flaw
A whitehat moved 3,832 NFTs out of hundreds of wallets
A whitehat moved 3,832 non-fungible tokens (NFTs, digital collectibles recorded on a blockchain) from hundreds of wallets on Friday. The transfers happened after concerns were raised about a vulnerability involving the NFT marketplace Magic Eden.
A whitehat is a security-minded actor who uses a weakness in a system to protect assets instead of stealing them. The tokens were moved to a single receiving wallet, according to the people who tracked the activity.
How the transfers were first spotted
An NFT community member known on X as Cirrus flagged the activity on Friday. Cirrus said one wallet had moved 3,832 NFTs from hundreds of wallets, and that the transactions appeared as sales through Magic Eden.
Cirrus advised NFT holders to revoke permissions as a precaution. Revoking a permission, also called an approval, removes the right a user once gave to a contract to move their tokens.
Yuga Labs says the NFTs are safe and will be returned
Shortly after, 0xQuit, the pseudonymous vice president of blockchain at Yuga Labs, said the transfers were part of a white-hat operation. He said the NFTs in the receiving wallet are safe and "will be returned once they are no longer at risk."
Yuga Labs CEO Michael Figge said a vulnerability had been discovered a few hours earlier and that the company would share more information soon.
0xQuit has taken part in similar rescue efforts before. In June, he helped recover 68 NFTs worth more than $500,000 after an exploit hit Flooring Protocol. Those assets were later held for return to affected users.
What Magic Eden says about the affected contract
Magic Eden said on X that the exploit involved Limit Break's Payment Processor V2, an NFT trading protocol the marketplace stopped using in October 2024. The company also said it closed its EVM marketplace in the first quarter of 2026.
"No live Magic Eden listings were impacted in this exploit," the company said. It added that NFTs listed on its EVM marketplace from about February to October 2024 could be affected.
Magic Eden urged former users to revoke approvals for the contract on Ethereum, Polygon and Base. It noted that revoking will not bring back tokens that have already been moved. The company said it was contacting Limit Break, which owns and maintains the protocol, about further steps, including efforts to pause transfers.
What is confirmed so far
- 3,832 NFTs were moved from hundreds of wallets on Friday.
- The transfers were described by Yuga Labs' 0xQuit as a white-hat operation, and he said the NFTs will be returned once the risk passes.
- Magic Eden linked the issue to Limit Break's Payment Processor V2, a protocol it stopped using in October 2024.
- Magic Eden said no live listings were affected and that NFTs listed on its EVM marketplace from roughly February to October 2024 could be affected.
- Magic Eden asked former users to revoke approvals for the contract on Ethereum, Polygon and Base.
What is still unclear
The exact nature of the vulnerability has not been explained. It is not yet known when the rescued NFTs will be returned, whether any additional wallets are affected, or what further action Limit Break might take. The identity of the whitehat has not been confirmed.
Why this matters for NFT holders
Permissions given to a contract can stay active long after a marketplace stops using that contract. That means people who listed NFTs on Magic Eden's EVM marketplace in 2024 may still need to revoke those approvals, even though the marketplace has since closed. Revoking removes future risk, but it does not undo transfers that have already happened.
What happens next
Magic Eden said it is working with Limit Break on further mitigations, including possible efforts to pause transfers. Yuga Labs said more information would be shared soon.