Newsroom
25 September, 2026 / News / AI / Tags: magic, nfts, eden, xquit, whitehat

A protective transfer of thousands of NFTs from hundreds of wallets followed discovery of a vulnerability in an older trading protocol once used by the marketplace
A whitehat operation transferred 3,832 non-fungible tokens from hundreds of wallets on Friday amid concerns over a security vulnerability tied to an older NFT trading protocol previously integrated with Magic Eden. The assets, moved at zero Ether and estimated at $1.4 million in value, include pieces from collections such as Bored Ape and Azuki.
Community member Cirrus first flagged the activity, noting that a single wallet had executed the transfers, which appeared as sales routed through Magic Eden. Holders were immediately advised to revoke NFT permissions as a precautionary step.
Yuga Labs’ pseudonymous vice president of blockchain, known as 0xQuit, stated that the transfers formed part of a deliberate whitehat effort rather than malicious activity. The NFTs now reside in a designated receiving wallet and remain secure.
0xQuit has prior experience with similar rescues. In June, the same individual assisted in recovering 68 NFTs valued at more than $500,000 following an exploit affecting Flooring Protocol, with those assets later returned to owners.
Yuga Labs CEO Michael Figge confirmed that the vulnerability had been identified several hours earlier and indicated that further details would be shared once available. The response was being managed by 0xQuit’s team.
Magic Eden clarified that the issue involved Limit Break’s Payment Processor V2, an NFT trading protocol the marketplace discontinued in October 2024. The company closed its EVM marketplace during the first quarter of 2026.
Only NFTs that had been listed on the EVM marketplace roughly between February and October 2024 could be affected. Magic Eden directed former users to revoke approvals for the relevant contract on Ethereum, Polygon and Base. The company noted that revocation would not reverse tokens already transferred and said it was coordinating with Limit Break on additional measures, including potential pauses on transfers.
Users who previously listed assets or granted transfer permissions through Magic Eden were specifically urged to revoke unnecessary approvals for the Ethereum Payment Processor V2 and ApeChain Payment Processor V3 contracts. The episode centers on residual marketplace approvals that can remain active even after a user ceases regular platform activity.
The protective transfers occurred while the underlying risk remained unresolved. Officials involved in the response have indicated that the secured NFTs will be restored to their original holders once the vulnerability no longer poses a threat. Holders continue to be advised to review and revoke outdated contract permissions across supported chains as a standard security practice.








