Magic Eden Users Reclaim Stolen NFTs After $2.8M Exploit
A security exploit on Magic Eden in September 2026 exposed users to potential NFT theft. The attacker used an active permission from a Payment Processor V2 approval that was never turned off, even after Magic Eden dropped the processor in October 2024.
The exploit affected wallets on Ethereum, Polygon, Base, Arbitrum, and ApeChain, with at least $2.8 million stolen since its inception on September 24. The whitehat behind the rescue mission, 0xQuit, said that someone abused the bug to steal various NFTs, including Meebits, Otherdeeds, World of Women NFTs, and Desperate ApeWives.
The rescue effort saved 23,155 NFTs worth over $5.7 million, but some collections may be unable to release cleanly due to transfer validator rules. Magic Eden advised users to revoke the V2 approval on Ethereum, Polygon, and Base, while OpenSea co-founder Chris Maddern flagged more than 3,000 items as stolen.