MAGIC (MAGIC): Whitehat Rescue Saves 23,155 NFTs Worth $5.7M in Magic Eden Exploit
A Payment Processor V2 exploit exposed old Magic Eden listings. Whitehats rescued 23,155 NFTs worth over $5.7M, though 660 WETH was lost.
AI SummaryAI
- Whitehat rescuers moved 23,155 NFTs worth over $5.7 million during the Magic Eden exploit response.
- An attacker stole 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives via Payment Processor V2.
- Whitehats transferred 3,832 NFTs from hundreds of wallets in the initial rescue sweep.
- About 660 WETH exposed to a reverse version of the exploit was not recovered.
Whitehat Rescue of 23,155 NFTs
Magic Eden warned on Friday that NFTs listed on its now-closed EVM marketplace — covering Ethereum and its compatible chains — between roughly February and October 2024 remain exposed to an exploit in Limit Break's Payment Processor V2, an NFT trading and settlement protocol. Yuga Labs vice president of blockchain Quit (0xQuit) disclosed in a detailed post on X that an attacker abused the bug at 9AM EST to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives. Magic Eden adopted the contract to settle trades in 2024, stopped using it that October and shut its EVM marketplace entirely in early 2026 — yet lingering PayFi-style settlement permissions kept old listings at risk. “No live Magic Eden listings were impacted,” the company stated.
Hundreds of Wallets Touched
Early indications understated the blast radius. The first sweep moved 3,832 NFTs out of hundreds of wallets — a figure that captured only the opening hours of the response. A whitehat rescue, in this context, is an operation in which trusted security researchers transfer vulnerable assets into safe custody before attackers can reach them, returning them once the risk is cleared. The suspected flaw was reported to Yuga Labs' blockchain team more than 12 hours after the initial theft, according to 0xQuit's timeline, giving the attacker a long head start. The warning also landed a day after unknown hackers drained more than $380 million in Ethereum and other assets from the Bitget exchange, in what security trackers describe as the largest crypto hack of the year.
The ability of whitehats to move assets without owner signatures highlights how permissive the old approval model was. When users list NFTs, they typically grant a contract sweeping “approved for all” permission to move their tokens, and that permission stays active until it is explicitly revoked — meaning anyone who can invoke the compromised settlement path effectively controls the assets. Limit Break paused Payment Processor V3, which carried the same flaw, but V2 could not be paused, leaving a coordinated transfer as the only defense. Users who never touched the marketplace since 2024 may still hold live permissions on contracts they assume are dormant — a risk that sits directly at the intersection of private-key security and marketplace plumbing.
Magic Eden's Revoke-First Response
Magic Eden's guidance is unambiguous: anyone who listed or traded on its EVM marketplace should revoke the V2 contract's “approved for all” permissions on Ethereum, Polygon and Base using Revoke.cash. The company cautioned that revoking will not return tokens that have already moved, and that listings created after October 2024 are expected to be unaffected. It also confirmed it stopped using Payment Processor V2 in October 2024 and closed the EVM marketplace in the first quarter of 2026, so no active listings were exposed. The marketplace, which rose on Solana with automated market maker (AMM) liquidity pools before expanding multichain, dropped Ethereum and Bitcoin support in February to focus on Solana and its crypto casino, Dicey.
660 WETH Unrecovered as Rescue Closes
The final tally shows both the operation's scale and its cost. Yuga Labs CEO Michael Figge said the flaw was identified only hours before the response began, while 0xQuit confirmed that all told, 23,155 NFTs worth north of $5.7 million were moved to safety, with owners able to reclaim them after revoking approvals. Roughly 660 WETH exposed to a reverse version of the exploit could not be recovered in time. Quit published the Payment Processor V2 (Ethereum) and V3 (ApeChain) contract addresses for users to revoke, and Magic Eden said it continues investigating alongside Limit Break on further mitigation. Recovered NFTs are consolidated at an address beginning 0x71cF pending safe return.
Dormant Approvals Are the Real Attack Surface
Read together, these developments trace one arc: a dormant marketplace kept alive by dormant permissions. COINOTAG's reading of the primary record — 0xQuit's own post and the published contract addresses, which function as the de-facto incident filing — confirms the core numbers: 23,155 NFTs protected above $5.7 million, 3,832 moved in the opening sweep, and 660 WETH lost to the reverse path. Whitehat rescues operate as informal DeFi insurance: community-run loss mitigation without a policy or a premium. The load-bearing lesson for holders is procedural, not speculative — approvals granted years ago on platforms that have since pivoted or shut down remain live attack surface until revoked.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


