Whitehat moves 3,832 NFTs from hundreds of wallets after Magic Eden scare
A whitehat operation shifted 3,832 NFTs from hundreds of wallets over concerns about a vulnerability tied to Magic Eden, with Yuga Labs saying the assets are safe and will be returned.

Key points
- A single wallet moved 3,832 NFTs from hundreds of wallets on Friday, according to NFT community member Cirrus on X.
- Cirrus said the transactions appeared as sales through Magic Eden and urged holders to revoke NFT permissions.
- Yuga Labs' 0xQuit said the transfers were a whitehat operation and the NFTs "will be returned once they are no longer at risk."
- Yuga Labs CEO Michael Figge said a vulnerability was found a few hours earlier and more information would follow soon.
- Magic Eden has not publicly confirmed any exploit of its contracts and had not responded to Cointelegraph's request for comment.
A whitehat moved 3,832 non-fungible tokens out of hundreds of wallets on Friday, after concerns emerged about a vulnerability involving the NFT marketplace Magic Eden, Cointelegraph reports. The transfers were first spotted by an NFT community member known as Cirrus on X, who said a single wallet had taken the 3,832 NFTs from hundreds of separate wallets.
Cirrus said the transactions appeared on-chain as sales made through Magic Eden, and advised NFT holders to revoke their permissions as a precaution. Revoking permissions is a common defensive step for wallet owners who fear a contract or marketplace approval could be used to move their assets without consent.
Shortly afterwards, Yuga Labs' pseudonymous vice president of blockchain, 0xQuit, said the transfers were part of a whitehat operation rather than a theft. He said the NFTs sitting in the receiving wallet are safe and will be returned once they are no longer at risk. The Yuga Labs executive has taken part in similar NFT rescue efforts before.
Transfers spotted on-chain
In June, 0xQuit helped recover 68 NFTs worth more than $500,000 after an exploit hit Flooring Protocol, with those assets later held so they could be returned to affected users. That earlier episode followed a similar pattern, in which assets were moved to safety while the underlying risk was assessed.
Yuga Labs CEO Michael Figge said a vulnerability had been discovered a few hours before the transfers and that the company would share more information soon. Magic Eden itself has not publicly confirmed that its contracts were exploited. Cointelegraph said it contacted Magic Eden for comment but had not received a response by publication.
The episode highlights how quickly assets can be moved when a marketplace or contract approval is suspected of being unsafe, and how whitehats sometimes step in before an attacker does. It also shows the difficulty holders face in telling a rescue from a theft while transactions are still unfolding on-chain.
Whitehat operation confirmed
For now, the reported position is that the 3,832 NFTs are being held rather than lost, and that their return depends on the risk passing. Until Magic Eden confirms or denies an exploit, the exact nature of the vulnerability remains unconfirmed by the marketplace.
