Bitcoin.com News
Powered by

White Hats Swipe $5.7M in NFTs Before Attackers Get Their Shot

A wallet suddenly pulled thousands of NFTs from hundreds of owners for 0 ETH early Friday, setting off alarms around Magic Eden. Except the wallet belonged to a white-hat rescue operation. Yuga Labs’ 0xQuit says the team ultimately secured 23,155 NFTs worth more than $5.7 million after discovering a bug involving old Limit Break Payment Processor approvals.

WRITTEN BY
SHARE
White Hats Swipe $5.7M in NFTs Before Attackers Get Their Shot

Key Takeaways

  • 0xQuit says white hats managed to rescue 23,155 exposed NFTs worth more than $5.7 million before attackers could reach them.
  • Cirrus first raised the alarm after spotting 3,832 NFTs moving from hundreds of wallets through apparent Magic Eden sales for 0 ETH.
  • 0xQuit says roughly 660 WETH slipped through before the rescue, while holders with old approvals are being urged to revoke them.

Thousands of NFTs Suddenly Move for Nothing

It looked awful onchain. Thousands of NFTs were leaving hundreds of wallets, each transfer appearing as a Magic Eden sale for precisely 0 ETH.

NFT tracker Cirrus sounded the alarm early Sept. 25 after spotting 3,832 NFTs moving into a single wallet. Minutes later, Yuga Labs VP of Blockchain 0xQuit stepped in with the twist: “hey ya this is a whitehat and everything in [the wallet 0x71cF] is safe and will be returned once they are no longer at risk.” The rescue was much bigger than first thought.

Old Approvals Come Back to Bite

0xQuit later said white hats secured 23,155 NFTs valued north of $5.7 million after a vulnerability was discovered in Limit Break’s Payment Processor. Magic Eden previously used the protocol for Ethereum trades before closing its EVM marketplace in March. The marketplace disappeared. Some wallet approvals didn’t.

According to 0xQuit, an attacker first stole 10 Meebit non-fungible tokens, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate Apewives. Once the wider exposure became clear, white hats began moving vulnerable NFTs into custody before attackers could reach them.

There was another catch. The same vulnerability could reportedly be used against WETH, and roughly 660 WETH wasn’t recovered. 0xQuit described it as “the $1.7M in WETH I wasn’t fast enough for.”

Owners Still Need to Revoke

The rescue doesn’t automatically kill the vulnerable approvals. Holders who previously interacted with Magic Eden’s Ethereum marketplace have been urged to revoke Limit Break Payment Processor V2 approvals on Ethereum and V3 approvals on ApeChain.

Rescued NFTs are expected to be returned after affected owners revoke those permissions, but no public claim date has been announced. At 6:44 a.m. Eastern time on Friday, Magic Eden summarized what happened. The official X account said the exploit involves Limit Break’s Payment Processor V2, an NFT trading protocol the marketplace used to settle EVM trades in 2024.

The company stopped using the protocol in October 2024 and shut down its EVM marketplace in the first quarter of 2026. “No live Magic Eden listings were impacted in this exploit,” the company claimed, though NFTs listed on its EVM marketplace between roughly February and October 2024 could potentially be affected.

The Magic Eden team stressed that it is working with Limit Break, which owns and maintains the protocol, while investigating additional mitigation measures. The company also credited 0xQuit for the “white hat rescue” and for flagging the vulnerability.

Users who listed or traded NFTs on Magic Eden’s EVM marketplace before it closed are being urged to revoke approvals associated with the affected Payment Processor V2 contract on Ethereum, Polygon, and Base. Magic Eden cautioned that “revoking does not return tokens that already moved” and emphasized its investigation remains ongoing.