Thousands of digital collectibles were suddenly sold for 0 ETH on the Magic Eden platform on September 25, 2026. An NFT trader named Cirrus was the first to highlight a series of zero-cost asset transfers moving from the platform to a single destination address.
In response to this wave of 0 ETH transactions, Cirrus immediately issued a stern warning to all users who had ever interacted with Magic Eden smart contracts. He urged them to promptly revoke contract permissions or approvals from their crypto wallets to prevent ongoing losses.
Notably, this exploit occurred within the platform’s legacy EVM (Ethereum Virtual Machine) contracts, despite its EVM marketplace already being shut down. Magic Eden previously discontinued support for its Bitcoin and EVM-based NFT marketplaces earlier this year, with EVM operations officially terminating on March 9.
Rescue Operation Claims
Amid confusion among NFT collectors, an anonymous entity on the social media platform X using the pseudonym ‘Quit’ emerged with a different narrative. Quit claimed that the series of 0 ETH asset transfers was not a malicious theft, but purely a whitehat or ethical hacking operation.
According to Quit, all transferred NFT assets are currently secure from potential malicious hackers. Quit shared the wallet address 0x71cf3f5724bD2B72Ef6464992aCd26216DE7fe33 as the holding destination and promised that all assets would be returned to their original owners.
However, these statements remain unverified claims from Quit. As of publication time, Magic Eden has yet to release an official statement confirming whether its platform is indeed experiencing a security breach.
Losses Yet to Be Disclosed
Without confirmation from the platform developers, there is no guarantee that the 0x71cf3f5724bD2B72Ef6464992aCd26216DE7fe33 address genuinely belongs to a legitimate ethical hacker. The exact scale and nature of the incident remain unclear, as Magic Eden has not yet disclosed the total number of transferred NFTs or their estimated value.
This incident demonstrates that legacy smart contracts whose user interfaces have been decommissioned continue to operate on the blockchain, and vulnerabilities within them can still be exploited at any time by third parties.
For anyone who previously connected a crypto wallet to Magic Eden’s EVM network, revoking contract approvals now is the only safe measure. Until an official statement guarantees system security, self-revoking permissions remains the best defense against further exploitation.
Reported by crypto.news.
Read also: What Are NFTs and How Do They Work?
Read also: First Zcash ETP Enters European Exchange After ZEC Surges 2,700% - But Fees Are Well Above Bitcoin
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




