A whitehat moved 3,832 non-fungible tokens from hundreds of wallets on Friday after concerns surfaced over a vulnerability tied to NFT marketplace Magic Eden.
NFT community member Cirrus first flagged the activity on X, saying a single wallet had transferred 3,832 NFTs out of hundreds of wallets. Cirrus said the transactions appeared onchain as sales through Magic Eden and urged NFT holders to revoke permissions as a precaution.
Shortly after, Yuga Labs’ pseudonymous vice president of blockchain, 0xQuit, said the movements were part of a whitehat operation. He said the NFTs now sitting in the receiving wallet are safe and "will be returned once they are no longer at risk."
0xQuit has taken part in similar recovery efforts before. In June 2026, he helped recover 68 NFTs worth more than $500,000 after an exploit hit Flooring Protocol. Those assets were later held for return to affected users.
Yuga Labs CEO Michael Figge said a vulnerability had been discovered a few hours earlier and that the company would share more information soon.
Magic Eden says exploit involved Limit Break’s Payment Processor V2
Magic Eden later said on X that the exploit involved Limit Break’s Payment Processor V2, an NFT trading protocol the company stopped using in October 2024. It also said its EVM marketplace was shut down in the first quarter of 2026.
"No live Magic Eden listings were impacted in this exploit," the company said. It added that NFTs listed on its EVM marketplace from approximately February to October 2024 could be affected.
Magic Eden urged former users to revoke approvals for the contract on Ethereum, Polygon and Base. The company noted that revoking approvals would not bring back tokens that had already been moved.
It also said it was in contact with Limit Break, the protocol’s owner and maintainer, about additional mitigations, including efforts to pause transfers.
Cointelegraph said it had contacted Magic Eden for comment but had not received a response by the time of publication.

