DropsTab logo - blue line depicting the shape of a water drop with Christmas decoration
M. Cap:Ā $2.90Ā TĀ 0.47%24h Vol:Ā $111.35Ā BĀ āˆ’37.08%BTC:Ā $83,955.00Ā 0.48%ETH:Ā $2,686.52Ā 0.01%S&P 500:Ā $7,743.18Ā 0.55%Gold:Ā $4,286.20Ā 0.43%BTC Dominance:Ā 58.20%

Magic Eden Suspected of Hacking: A white hat from Yuga Labs withdrew 3,832 NFTs from hundreds of wallets to prevent hackers from stealing them.

25 Sep, 2026byDropsTab
Join Our Socials

What happened. On the morning of September 25, the CirrusNFT tracker noticed that one wallet had taken 3,832 NFTs from hundreds of different Ethereum wallets. All the transfers appeared as transactions on Magic Eden at a price of 0 ETH—meaning someone was ā€œsellingā€ other people’s NFTs to themselves using previously issued permissions.

Who did it. Yuga Labs CEO Michael Figge reported that the vulnerability was discovered several hours ago and that a team member named Quit is handling the recovery of the assets. Quit himself confirmed that this was a white-hat operation: everything on the address 0x71cF…fe33 is safe and will be returned to the owners once the risk has been eliminated. This isn’t the first such incident: in June, 0xQuit also took 68 high-value NFTs from Flooring Protocol into Yuga Labs’ custody while they were still protected from attackers.

What’s inside. Among the recovered NFTs are BAYC, MAYC, Azuki, Doodles, Moonbirds, CloneX, Meebits, and other collections. One trader estimated the total value at around $1.4 million, though this figure hasn’t been confirmed.

Why it happened (version). The suspected cause: old approvals for the contract of the former Ethereum marketplace Magic Eden. In spring 2026, the platform shut down Bitcoin and EVM-based features to focus on Solana, but some of the permissions apparently remained active. According to Magic Eden’s documentation, support for the EVM marketplace ended on March 9. The mechanism hasn’t been officially confirmed yet, and there’s no official investigation into the incident so far.

What to do. If you’ve ever listed NFTs on Magic Eden in Ethereum, revoke the approvals via revoke.cash. The main threat right now is impersonators who could use the same permissions. Don’t sign any unexpected ā€œclaimā€ or ā€œreturnā€ transactions—after public rescue operations, phishing attempts usually become more active.

As of publication, Magic Eden hasn’t issued an official statement, and details about the vulnerability, the number of affected wallets, and the total value of the assets remain undisclosed. If the company releases a comment, this post will be updated.

ME token does not react negatively

ME token does not react negatively

Continue reading this article on source:Ā x.com