At 9 AM EST on September 25, somebody abused a bug in an Ethereum settlement contract called Payment Processor V2. The first confirmed losses, listed by 0xQuit of Yuga Labs in his post-mortem thread, were 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. Each one left its owner’s wallet as a “sale” priced at zero.
NFT trader Cirrus spotted the wave from the outside and raised the alarm, watching a single wallet sweep 3,832 NFTs out of hundreds of different wallets and advising everyone to revoke their NFT permissions. Because the transfers executed through Magic Eden’s old marketplace flow, the initial assumption was that Magic Eden had been exploited. Minutes later, 0xQuit claimed the activity: this was a whitehat rescue, and everything moved to wallet 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 would be returned once the risk was closed.
Both stories were true. That is what makes this incident worth understanding.
The contract that outlived its marketplace
Payment Processor V2 is a marketplace settlement contract built by Limit Break, the game company behind DigiDaigaku. Magic Eden adopted it in early 2024 to settle trades on its Ethereum-facing marketplace, then stopped using it in October 2024, and shut the EVM marketplace entirely in the first quarter of 2026.
Here is the problem. When you list an NFT on a marketplace that uses operator-based settlement, you grant the contract a setApprovalForAll permission over that collection. The listing lives in the marketplace’s database. The approval lives on-chain in your wallet. Closing the marketplace, delisting the collection, even shutting down the frontend removes the listing. Nothing about any of that touches the approval.
The bug, as Blockaid traced it, made those dormant operator approvals executable again. An attacker could submit transactions that used Payment Processor V2 to impersonate NFT holders and acquire approved assets at a zero price. Before containment, Blockaid put the attacker’s take at roughly $1.7 million in NFTs across three transactions. The detail that matters for your own wallet hygiene: canceling listings and invalidating a master nonce did not remove the permission. Only an explicit revoke does.
This is the same class of exposure we cover in token approval safety: the approval is the attack surface, not the dApp you can see.
Why the rescue had to look like an attack
When Limit Break learned of the bug, it paused Payment Processor V3, which had a similar issue affecting some assets approved on ApeChain. V2 had no pause function. There was no patch, no kill switch, no support ticket. The only way to protect the exposed NFTs was to move them before the attacker got there, using the same mechanics the attacker was using.
That is what 0xQuit’s operation did through September 25. In total, 23,155 NFTs worth more than $5.7 million were relocated to the rescue wallet. A related exploit path that could drain WETH left 660 WETH at risk and unrecovered, roughly $1.8 million at the day’s ETH price.
We checked the rescue wallet on-chain ourselves. Within the first six pages of Etherscan’s transfer records alone, the wallet 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 absorbed more than 6,000 NFT transfers across at least 85 collections, pulled from more than 1,300 distinct source wallets, starting around 07:51 UTC. The scale of the sweep matches the story: this was not a targeted hit on a few whales, it was a mass evacuation of everyone still carrying the ghost approval.
If your NFT spent September 25 in that wallet, the assets are promised back. Follow 0xQuit’s thread for the return process, and be extremely suspicious of anyone DMing you an “expedited return” link. Post-incident phishing is the reliable second wave, the same pattern we documented in what to do after a wallet drainer hits.
Who actually needs to act
Magic Eden’s statement, as reported by Crypto Briefing: the company stopped using Payment Processor V2 in October 2024, closed the EVM marketplace in Q1 2026, no live listings were affected, and users who listed on the EVM marketplace between approximately February and October 2024 may still be exposed. Their guidance is to revoke the approved-for-all permissions.
If that is you, or if you touched any Ethereum NFT marketplace in 2024 that has since shut down:
Open revoke.cash or an equivalent approval scanner, connect the wallet you traded from, and look for setApprovalForAll entries pointing at settlement contracts for marketplaces you no longer use. Revoke them. Repeat for every wallet you have ever connected to an NFT marketplace, because the approval does not care whether you stopped trading, whether the marketplace still exists, or whether you think of that wallet as retired.
The uncomfortable lesson of September 25 is that “I don’t use that marketplace anymore” is not a security state. On-chain, you still do. A closed frontend with living approvals is not a dead product, it is an unattended vault with your signature on the door, waiting for whoever finds the bug first. For the broader pattern of how signed permissions turn into losses, see our guides on preventing wallet drainers and Permit-sign phishing.
Frequently Asked Questions
Was Magic Eden hacked?
Not its live systems, according to the company. Magic Eden says it stopped using Payment Processor V2 in October 2024 and shut its EVM marketplace in the first quarter of 2026, so no current listings were affected. The exploited contract was an old settlement layer that kept its permissions in user wallets long after the marketplace went dark.
Why didn't canceling my listing protect my NFTs?
Because the exposure was never the listing. It was the setApprovalForAll operator permission you granted when you used the marketplace. Security firm Blockaid confirmed the bug let old operator approvals execute zero-price transfers, and neither canceling listings nor invalidating a master nonce removes that permission. Only an explicit revoke does.
What should I do if I used Magic Eden's EVM marketplace in 2024?
Go to a token-approval revoker such as revoke.cash, connect the wallet you used, find approvals for the old marketplace settlement contracts, and revoke them. Magic Eden itself directed users who listed between approximately February and October 2024 to revoke their approved-for-all permissions. While you are there, revoke approvals for any other dead dApps you no longer use.