Magic Eden exploit: Whitehat secures 23,000+ NFTs

A vulnerability in Magic Eden’s former Ethereum marketplace led to NFT and WETH thefts. A whitehat secured 23,000+ NFTs, and users were urged to revoke contract approvals for protection.

Magic Eden recently faced a significant security breach involving its former Ethereum marketplace. A vulnerability in the Limit Break Payment Processor smart contract enabled attackers to steal at least 530.7 WETH and thousands of NFTs from users’ wallets. In response, a whitehat operation led by 0xQuit moved over 23,000 NFTs—worth around $6 million—into protective custody to prevent further losses. Specifically, 3,832 NFTs were transferred from hundreds of wallets as a precaution, with assurances that these assets would be returned once the threat was mitigated. Users were urgently advised to revoke approvals for affected contracts on Ethereum, ApeChain, Polygon, and Base, as simply cancelling listings or using hardware wallets did not offer protection. At the time of reporting, Magic Eden had not issued an official statement, leaving some uncertainty about the full scope of the breach.