📈 Get daily crypto insights that make you smarter about your money

Magic Eden Drains Itself? Thousands of NFTs Move for 0 ETH in Suspected Exploit Turned Whitehat Rescue

Ethereum NFT traders spent the morning of Sept. 25 watching a single wallet pull thousands of tokens out of hundreds of separate wallets through what looked like ordinary marketplace sales — except every sale was priced at zero ETH. The activity pointed at Magic Eden, one of the largest NFT marketplaces still operating, and forced an immediate question: was the marketplace contract exploited, or was something else unfolding behind the scenes?

NFT trader Cirrus flagged the activity first, reporting that a wallet had drained 3,832 NFTs from hundreds of different wallets with the transactions appearing to originate from Magic Eden. The immediate advice was blunt: anyone who had ever interacted with the marketplace should revoke their NFT approvals before their assets became the next line on the list.

Zero-price sales pointed at marketplace approvals

The pattern behind the warnings was unusual even by the standards of NFT security incidents. Whoever controlled the draining wallet was effectively selling NFTs to themselves for 0 ETH, using existing approvals that collectors had granted to Magic Eden contracts at some point in the past.

That mechanism matters because NFT marketplaces do not take custody of listed assets. Instead, users sign approvals that let the marketplace contract move specific tokens on their behalf once a sale completes. If an attacker finds a way to satisfy those approval conditions without a real buyer on the other end, the result looks exactly like what on-chain observers saw: valuable collections leaving their owners at a price of nothing.

Cirrus noted almost immediately that the wallet executing the transfers appeared to be funded from an address possibly linked to 0xQuit, a well-known NFT community figure — which raised the possibility that the entire operation was a whitehat rescue rather than an attack.

Quit claims the transfers are a whitehat operation

Minutes after the warnings spread, pseudonymous X user Quit confirmed that reading. In a post on X, Quit said the activity was a whitehat operation and that everything held at wallet 0x71cf3f5724bD2B72Ef6464992aCd26216DE7fe33 was safe and would be returned once the assets were no longer at risk.

If accurate, the claim reframes the morning’s events: rather than stealing NFTs, the operator would have used the vulnerable approval path to sweep at-risk collections into a holding wallet before an actual attacker could do the same thing. It is a maneuver with precedent in previous NFT contract incidents, where whitehats raced exploiters to drain funds and later returned them.

But the claim remains exactly that — a claim. Magic Eden has not confirmed that the address belongs to an authorized whitehat, that the transactions were part of a coordinated recovery effort, or that a vulnerability existed in the first place. At the time of writing, the marketplace had released no official statement confirming an exploit, leaving the nature and the scale of the incident unresolved.

What is still unknown

Several core details have not been disclosed. The vulnerability that may have allowed the transactions has not been described. The number of affected wallets has not been counted publicly. The total value of NFTs moved through the zero-price sales has not been tallied by the marketplace or by an independent auditor.

For holders, the practical guidance is the same in either scenario. Revoking old approvals costs a small amount of gas and removes the permission that made the transfers possible in the first place. Users who held valuable Ethereum NFTs and had interacted with Magic Eden in the past were advised to clear those approvals until the marketplace clarifies what happened.

The EVM marketplace was shut down months ago

The incident lands at an awkward moment in Magic Eden’s history. Earlier this year the company ended support for its Bitcoin and EVM-based NFT marketplaces, keeping its Solana marketplace as its core trading venue. The company’s own support documentation states that EVM marketplace support ended on March 9, with listings, bids and offers on that side hosted offchain and no longer visible or actionable after the shutdown.

That history creates an uncomfortable possibility: old approvals granted during the EVM marketplace era may have outlived the product itself. Approvals do not expire when a marketplace winds down a product line — they persist onchain until revoked or until the contract they point to is no longer able to execute.

Magic Eden’s current products still touch Ethereum collections. Its Packs product can contain NFTs from Ethereum collections, and NFTs revealed through Packs can be traded on the marketplace. The company has not said whether the Sept. 25 activity affected any of those services or involved contracts associated with the discontinued EVM marketplace.

A familiar risk for an aging market

The incident is a reminder that approval hygiene does not retire when a marketplace pivots. Ethereum NFT trading volume has fallen far from its peaks, but the approvals sitting in old wallets are denominated in assets, not in market sentiment — a dormant permission can move a valuable collection whether the market is hot or cold.

It also continues a rough stretch for NFT platform security. Earlier incidents this year ranged from marketplace contract bugs to phishing campaigns targeting collectors, and each one has reinforced the same defensive checklist: revoke unused approvals, keep valuable assets in a wallet that has never signed a marketplace permission, and treat any zero-price sale on a tracker as a reason to check permissions immediately.

For now, the thousands of NFTs sitting in the holding wallet are — according to the person who put them there — safe, and promised back to their owners once the risk has passed. Whether that promise holds is the question every affected collector is now waiting to see answered, and one Magic Eden will eventually have to address with more than silence.

This is a developing story and will be updated as Magic Eden responds. Market snapshot at 12:00 UTC on Sept. 25: BTC 84,606 USD, ETH 2,716.64 USD, SOL 120.81 USD.

24 thoughts on “Magic Eden Drains Itself? Thousands of NFTs Move for 0 ETH in Suspected Exploit Turned Whitehat Rescue”

  1. whitehat rescue through the same approval mechanism is a wild ending. one signer pulls 3,832 NFTs, gives them back, and we call it a happy story

  2. revoked my Magic Eden approvals the second i saw the Cirrus post. 3,832 NFTs moved for literally 0 ETH, insane that signatures from years ago can still do this

    1. same here, took me four minutes on revoke.cash. wild part is the sales showed up as normal marketplace activity, zero price and all. approvals are a time bomb

      1. four minutes is generous, my approvals page was three marketplaces deep. the part that spooks me is the 0 ETH sales rendering as normal activity

        1. worse, the 0 ETH sales rendered as completed listings. anyone lazy with portfolio trackers saw fake volume on their own collection

          1. fake completed listings in portfolio trackers is an underrated side effect. panic plus wrong data is how people make the worst decisions

        1. same experience, found a 2022 approval from a marketplace that doesnt even exist anymore. just sitting there waiting to be abused

      2. just did the same sweep and found live approvals from two marketplaces that shut down back in 2022. took me longer to find the revoke button than it did to sign all of them originally lol

        1. found an opensea approval from 2021 still live next to two dead marketplaces. revoked everything, feels gross that defaults are infinite

  3. everyone dunking on NFTs but this is purely an approvals problem. any marketplace you ever signed can pull your stuff if the signer gets compromised. lesson cost 3,832 NFTs today

  4. selling NFTs to yourself for 0 ETH through stale approvals is such a clean exploit path. no key theft needed, the approvals were the keys

    1. yep, the approval was the private key all along. any signature older than a year sitting in your wallet is unpatched attack surface

      1. the approval is the private key all along, gonna be quoting that one for years. infinite approval defaults should have died after 2022, unreal they are still standard

    2. agreed, and marketplaces not taking custody is exactly why. every approval you sign is a standing instruction someone can abuse

      1. Exactly, and this rescue proves the same mechanism works for heroes and drainers alike. The contract has no morals, it just executes

    3. and that same path returning everything is why 0xQuit walks away a legend. one signer choosing to be nice is a heck of a security model for a whole industry to rely on

  5. 0xQuit giving everything back is the only reason this isnt a 3,832 NFT obituary. revoked my approvals anyway, trust is not a wallet feature

  6. Whitehat or not, Magic Eden asking everyone to trust the same approval system next week is bold. Revoke and re-sign carefully, folks.

  7. my Magic Eden signature predated their contract migration and still worked. purged everything an hour after the Cirrus post, approvals older than the marketplace itself

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$83,904.00-0.4%ETH$2,690.61+0.6%SOL$120.34+3.6%BNB$775.15-0.5%XRP$1.58+4.6%ADA$0.2544+2.8%DOGE$0.0976+2.4%DOT$1.18+1.3%AVAX$10.40+0.4%LINK$13.86+8.7%UNI$9.59+4.0%ATOM$1.78+0.3%LTC$70.06-5.4%ARB$0.2216+2.6%NEAR$5.13+12.2%FIL$1.03+3.2%SUI$1.11+11.0%BTC$83,904.00-0.4%ETH$2,690.61+0.6%SOL$120.34+3.6%BNB$775.15-0.5%XRP$1.58+4.6%ADA$0.2544+2.8%DOGE$0.0976+2.4%DOT$1.18+1.3%AVAX$10.40+0.4%LINK$13.86+8.7%UNI$9.59+4.0%ATOM$1.78+0.3%LTC$70.06-5.4%ARB$0.2216+2.6%NEAR$5.13+12.2%FIL$1.03+3.2%SUI$1.11+11.0%
Scroll to Top