Scouted the hot spot: Magic Eden’s old contract sparked a big stir—on-chain monitoring spotted an address drained with 0 ETH, and in a short time around 3,832 Ethereum blue-chip NFT tokens were moved from several hundred wallets. It includes Bored Apes and Azuki, estimated value roughly $1.4 million. The community’s first reaction was, “Here we go again.”
Soon, 0xQuit, Yuga Labs’ blockchain VP and security expert, came out to say this is a white-hat rescue: the assets are all in the address 0x71cF…fe33, and once the risk is cleared, they will be returned. CEO Michael Figge also confirmed that the vulnerability was discovered just a few hours ago, and everything is being handled by the 0xQuit team.
Earlier this year, Magic Eden already shut down its Ethereum and Bitcoin markets and shifted its focus to Solana, but the authorizations from the old Ethereum contract were still active, which became the entry point for this incident. As of the time of writing, there has been no official statement.
0xQuit recommends that anyone who previously placed orders on Magic Eden or granted approvals revoke those old permissions as soon as possible using tools like revoke.cash—especially Ethereum Payment Processor V2 and ApeChain Payment Processor V3. If your assets were moved, don’t panic for now; reports say everything is currently safe. Also, don’t click any unofficial links promising “compensation claims” or “security verification.”
Old marketplace contract approvals have always been left hanging, and the risk won’t just disappear on its own. #NFT #MagicEden #Safety
Soon, 0xQuit, Yuga Labs’ blockchain VP and security expert, came out to say this is a white-hat rescue: the assets are all in the address 0x71cF…fe33, and once the risk is cleared, they will be returned. CEO Michael Figge also confirmed that the vulnerability was discovered just a few hours ago, and everything is being handled by the 0xQuit team.
Earlier this year, Magic Eden already shut down its Ethereum and Bitcoin markets and shifted its focus to Solana, but the authorizations from the old Ethereum contract were still active, which became the entry point for this incident. As of the time of writing, there has been no official statement.
0xQuit recommends that anyone who previously placed orders on Magic Eden or granted approvals revoke those old permissions as soon as possible using tools like revoke.cash—especially Ethereum Payment Processor V2 and ApeChain Payment Processor V3. If your assets were moved, don’t panic for now; reports say everything is currently safe. Also, don’t click any unofficial links promising “compensation claims” or “security verification.”
Old marketplace contract approvals have always been left hanging, and the risk won’t just disappear on its own. #NFT #MagicEden #Safety
