VERSE PRESS

Crypto News, Global First.

Whitehat Races Malicious Actors to Secure 23,155 NFTs Exposed by Dead Marketplace's Lingering Permissions

A flaw in a deprecated smart contract used by Magic Eden's now-closed EVM marketplace put more than $5.7 million in NFTs at risk on September 25. Yuga Labs' VP of Blockchain beat attackers to most of them.

|

A vulnerability in Limit Break's Payment Processor V2, a smart contract that once handled NFT trades on Magic Eden's Ethereum, Polygon, and Base marketplace as well as other platforms, allowed anyone to transfer tokens from affected wallets at zero cost by exploiting the AcceptOfferERC721 event within the contract. The flaw targeted stale "approval" permissions that users granted when listing NFTs between February and October 2024. Those permissions never expired when Magic Eden shut down its EVM operations in March 2026, leaving wallets quietly exposed for more than six months after the platform closed.


The incident surfaced publicly around 06:31 UTC Friday when NFT researcher CirrusNFT flagged a single wallet sweeping 3,832 tokens from hundreds of accounts, each recorded on-chain as a 0 ETH sale. Minutes later, 0xQuit, the VP of Blockchain at Yuga Labs, confirmed he had already begun a whitehat response: moving vulnerable assets to a secure rescue wallet before malicious actors could reach them. The rescue wallet address is 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33. The first confirmed rescue transaction hit block 26,052,469 at 05:46:47 UTC. By the time 0xQuit posted a full account at 09:06 UTC, he had secured 23,155 NFTs across more than 447 collections including Bored Apes, Azuki, CloneX, and Art Blocks. "Worked through the night to save about $6 million of NFTs and was left thinking about the $1.7M in WETH I wasn't fast enough for," he wrote.


The $1.7 million in WETH (Wrapped Ether, approximately 660 WETH) refers to a parallel exposure. The same approval mechanism that allowed NFT transfers also left pre-approved WETH balances accessible to attackers. That portion could not be recovered in time. Malicious actors also managed to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives before the whitehat rescue reached them. Yuga Labs CEO Michael Figge confirmed the operation publicly, stating that a team member was "currently conducting a white-hat rescue operation."


The technical root cause traces to a design choice in Payment Processor V2. Unlike its successor, V3, the contract had no pause function. When Limit Break identified the vulnerability and paused V3 on ApeChain (contract address 0x9a1D00000000fC540e2000560054812452eB5366), V2 on Ethereum (contract address 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834) remained fully active with no administrative override available. The only mitigation was speed. The vulnerability itself exploits how ERC-721 approvals work on Ethereum-compatible chains: when a user lists an NFT on a marketplace, they sign a "setApprovalForAll" transaction that gives the marketplace contract permission to move any token in that collection on their behalf. That permission is written to the blockchain permanently and does not cancel itself when a platform closes. Users must revoke it manually. Magic Eden's statement acknowledged the problem and pointed to Payment Processor V2 as the source, noting the company stopped using it in October 2024 and that tokens currently listed on its active Solana marketplace are not affected. Other platforms that integrated Payment Processor V2 may carry similar exposure.


Revoke.cash, a tool that helps users manage and cancel on-chain permissions, deployed a dedicated checker for this incident at 09:11:39 UTC. Any user who listed or traded NFTs on Magic Eden's EVM marketplace, or on other platforms that integrated Payment Processor V2 including Mintify, Otherside, and ApeChain-connected platforms, during the affected window should visit revoke.cash and cancel approvals on Ethereum, Polygon, and Base. Cancelling an active listing is not enough. Approvals are a separate on-chain action and must be revoked independently. Given the scale of this incident and the return process not yet announced, users should exercise caution: do not interact with any smart contract or website claiming to help you "claim" or "recover" your NFTs unless official instructions have been published by Yuga Labs or Magic Eden.


The incident carries particular weight for NFT holders in South Asia and Africa, two regions with substantial EVM activity. India holds the highest NFT adoption rate of any country at 15.5%, and Nigeria ranks among the top global markets for crypto wallet ownership, with more than 84% of internet users reporting they hold a wallet. South Africa also shows high crypto penetration, with approximately 66% wallet ownership among internet users. Polygon, one of the three chains affected, has been a primary entry point for traders in both regions due to its low transaction fees. Users in these markets who interacted with Magic Eden EVM in 2024 may not have tracked the platform's March 2026 closure closely, and the approvals they signed remain active. Awareness of revocation tools is the main gap. No regional breakdown of affected wallets has been confirmed; the above represents analyst assessment of likely exposure rather than verified loss data.


This is the second whitehat operation 0xQuit has led in 2026. In June, he led a collaborative rescue of 68 blue-chip NFTs worth roughly $570,000 from a compromised Flooring Protocol position, working alongside security researcher Coffee and liquidity provider GrailsOTC, who fronted the capital needed to pull assets from compromised pools.

The pattern points to a structural gap in how NFT infrastructure handles decommissioning. Platforms that shut down contracts without prompting users to revoke permissions leave a long tail of exploitable approvals on-chain. The March 2026 GONDI NFT lending protocol exploit, which resulted in approximately $230,000 in losses through the same stale-approval mechanism, illustrates how recurring this failure mode has become. Revoke.cash has documented more than $200 million in total approval-based losses across 2024 and 2025.

Limit Break has not published an incident postmortem as of publication, and the return process for rescued assets has not yet been announced. Users holding NFTs in the rescue wallet should wait for official instructions from Yuga Labs or Magic Eden before taking any action.