An emergency alert spread across NFT trading desks on Sept. 25 after 3,832 NFTs were transferred from hundreds of user wallets for 0 ETH, in what desks are treating as a suspected Magic Eden exploit involving the marketplace’s linked contracts. On-chain monitoring first flagged the anomalous zero-value executions early Friday morning. While a pseudonymous security researcher quickly claimed the actions were an authorized whitehat rescue, the lack of official marketplace confirmation leaves token holders exposed to unverified contract risks.
Unusual 0 ETH Transactions Spark Magic Eden Exploit Warnings
The alarm was first raised publicly by pseudonymous NFT trader Cirrus on Sept. 25. Cirrus published transaction logs demonstrating a single automated wallet draining thousands of tokens across hundreds of distinct user accounts without requiring ETH payments. The observed transactions routed through contracts historically associated with Magic Eden's marketplace router. The rapid drain of high-value digital collectibles triggered immediate concern across security channels.
Cirrus urged all collectors who previously approved Magic Eden smart contracts to revoke token permissions immediately. When users list assets or grant market routers unlimited token allowances, vulnerable or unhandled smart contract functions can allow third parties to transfer assets without settlement checks. Security advisories routinely highlight such permission risks, echoing broader industry efforts against cyber threats and exchange security vulnerabilities. Unrevoked allowances represent an ongoing attack vector until explicitly canceled on-chain.
Whitehat Claims Assets Secured at Designated Wallet Address
Shortly after Cirrus published the initial warning, pseudonymous security analyst Quit intervened on social media to claim responsibility for the asset movements. Quit stated that the operation was an active whitehat rescue designed to front-run potential malicious exploitation. According to Quit, all transferred digital assets were consolidated into wallet address 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 to prevent permanent loss.
Quit stated publicly that all assets held within the designated address remain safe and will be returned to original owners once underlying contract vulnerabilities are neutralized. However, this claim remains independently unverified. Magic Eden leadership and engineering teams have not publicly verified Quit's identity, nor have they confirmed that the rescue operation was coordinated with official authorization. Until formal verification occurs, market participants must treat the event as an unconfirmed security incident.
Legacy Approvals and Marketplace Discontinuation Context
Contextual background adds another layer of complexity to the incident. Magic Eden officially shut down its Bitcoin and Ethereum Virtual Machine (EVM) marketplaces on March 9, 2026, pivoting primary marketplace operations back toward its core Solana infrastructure. Additional details regarding network developments can be found in our coverage of Solana ecosystem performance and upgrades. Support documentation published during the March sunset stated that offchain listings and bids on EVM chains would cease to function.
However, ending frontend UI support does not automatically invalidate on-chain smart contract approvals. Smart contract approvals granted by users on Ethereum remain active on the blockchain indefinitely until users manually send revocation transactions. If legacy EVM router contracts contained an unpatched permission flaw, unrevoked user allowances could allow arbitrary asset transfers regardless of whether the frontend UI remains operational. Magic Eden also operates "Packs" containing EVM NFTs, but whether Packs contracts or legacy marketplace routers were involved remains unconfirmed.
What Remains Unverified in the Magic Eden Exploit Incident
At writing time, crucial technical and financial details remain undisclosed. Magic Eden has not released a post-mortem, confirmed an active exploit, or issued instructions to affected users. The exact smart contract vulnerability that enabled 0 ETH transfers has not been published, and the total monetary value of the 3,832 transferred NFTs remains uncalculated.
Furthermore, no official timeline or mechanics for returning assets from address 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 have been established by marketplace operators. Collectors who historically interacted with Magic Eden on Ethereum should immediately check wallet permissions using chain scanners or revocation tools. Will Magic Eden issue formal confirmation of the vulnerability, or will legacy EVM smart contract approvals continue to pose quiet risks to unsuspecting NFT holders?







































