Yuga Labs VP 0xQuit Confirms 23,155 NFT Rescue Worth $5.7M As 660 WETH Remains Exposed
A white-hat wallet pulled 23,155 NFTs worth more than $5.7 million from hundreds of owners for 0 ETH early Friday, September 25, 2026, in a coordinated rescue against an active exploit. Yuga Labs VP of Blockchain Quit, known publicly as 0xQuit, confirmed the operation after Magic Eden was initially suspected of hosting the vulnerability. The rescue secured assets across multiple collections before attackers could drain them, though roughly 660 WETH remained exposed and unrecovered at the time of the operation.
The incident began hours earlier when a white-hat actor moved 3,832 NFTs from hundreds of wallets, triggering alarms across Magic Eden's monitoring systems. Yuga Labs CEO Michael Figge said the issue was discovered within hours and that 0xQuit was handling affected assets within the scope of the white-hat rescue. The NFTs were secured at an address beginning with 0x71cF, according to statements posted through Wu Blockchain on X. Magic Eden has not yet disclosed the full scope of the issue or confirmed whether its own contracts were directly implicated.
Magic Eden Flags 0 ETH Transfers As White-Hat Rescue Unfolds
Magic Eden's monitoring systems flagged the unusual 0 ETH transfers on Friday as the white-hat rescue unfolded in real time. The marketplace initially appeared to be the source of the vulnerability, with early reports suggesting a security flaw in its infrastructure. The Cryptonomist reported on September 25, 2026, that thousands of NFTs moving for 0 ETH raised alerts for potential security risks and white-hat actions, though the outlet did not confirm the root cause at the time of publication.
The confusion stemmed from the mechanics of the exploit. NFTs were being transferred out of user wallets without any payment, a pattern that typically signals either a marketplace-level compromise or a contract vulnerability affecting multiple collections simultaneously. Magic Eden's silence during the first hours of the incident compounded the uncertainty. The marketplace had not yet disclosed the cause or full scope of the issue when Wu Blockchain published its initial thread at 08:18 UTC on September 25.
The scale of the transfers distinguished this event from routine marketplace activity. A single wallet moving 3,832 NFTs from hundreds of owners in a short window is not normal trading behavior. The 0 ETH price point eliminated the possibility of a coordinated buyout or collection sweep. This was either an attacker draining assets or a defender racing to secure them before the attacker could act.
Wu Blockchain Reports The Initial 3,832 NFT Movement
Wu Blockchain's first post on the incident, timestamped September 25, 2026 at 08:18 UTC, described Magic Eden as "suspected" of having a security vulnerability after a white hat moved 3,832 NFTs from hundreds of wallets. The post named Yuga Labs CEO Michael Figge as confirming the issue was discovered hours earlier. Figge said 0xQuit was handling affected assets within the scope of the white-hat rescue.
The initial 3,832 NFT figure later expanded to 23,155 NFTs as the rescue operation scaled. This expansion suggests the vulnerability affected a broader set of collections than initially identified. The white-hat team continued pulling at-risk NFTs throughout Friday as they mapped the full attack surface.
Magic Eden's Response Remains Limited
Magic Eden has not published a detailed technical post-mortem as of the latest available information. The marketplace's public response has been limited to monitoring alerts and internal investigation. This contrasts with the rapid disclosure from Yuga Labs and 0xQuit, who provided updates through social channels within hours of the first transfers.
The absence of a formal Magic Eden statement leaves open questions about whether the marketplace's contracts were directly involved or whether the vulnerability existed in a third-party payment processor that Magic Eden users had approved. The distinction matters for affected users, who need to know which approvals to revoke.
0xQuit Identified As Operator Behind The $5.7M NFT Rescue
0xQuit, the public handle of Yuga Labs VP of Blockchain Quit, was confirmed as the operator behind the white-hat rescue within hours of the first transfers. His role as both a Yuga Labs executive and an independent security researcher placed him in a unique position to coordinate the response. The H1DR4 case database lists Quit (@0xQuit) as the security researcher who reported the Flooring Protocol exploit on June 8, 2026, establishing a pattern of white-hat intervention in NFT infrastructure vulnerabilities.
The June 2026 Flooring Protocol incident provides critical context for Friday's rescue. In that earlier event, 0xQuit reported an exploit where attackers drained Flooring Protocol pools. White-hat researchers helped recover more than $500,000 in blue-chip NFTs from the same contracts vulnerability. The Asterix fork of Flooring Protocol was hit by a related exploit that drained roughly $40,000 in assets, according to Cryptopolitan reporting from June 8, 2026.
The recurrence of similar vulnerabilities across NFT infrastructure suggests a systemic weakness in payment processor contracts. 0xQuit's involvement in both the June and September incidents indicates he has become a de facto first responder for NFT ecosystem exploits. His dual role at Yuga Labs gives him both the technical expertise and the institutional mandate to act quickly.
The 0x71cF Address Holds The Rescued Assets
The rescued NFTs were secured at an address beginning with 0x71cF, according to 0xQuit's statements. This address serves as a temporary custody location while the vulnerability is patched and a return process is established. The use of a single custody address for 23,155 NFTs from hundreds of owners raises operational questions about how returns will be executed at scale.
The 0 ETH transfer mechanism means the NFTs were moved without any payment to the original owners. This is standard for white-hat rescues, where speed matters more than transactional formalities. The owners retain legal claim to their assets, but the NFTs are no longer in their wallets.
660 WETH Remains Unrecovered
A related exploit vector could be used to steal WETH, and approximately 660 WETH was not recovered in time, according to 0xQuit's statement. At the time of the incident, 660 WETH represented a significant additional loss beyond the NFT rescue. The WETH exposure suggests the vulnerability affected both NFT transfers and wrapped Ether balances held in the same contracts.
The unrecovered WETH complicates the narrative of a fully successful rescue. While 23,155 NFTs were secured, the 660 WETH loss demonstrates that the white-hat team was racing against active exploitation. Some assets were already gone before the rescue could reach them.
Yuga Labs Collection Vulnerability Targeted In Friday Rescue
The vulnerability was ultimately traced to Limit Break Payment Processor V2, not Magic Eden's core marketplace contracts. 0xQuit confirmed this finding in his September 25 statement, correcting the initial suspicion that Magic Eden was the source. Limit Break is a payment processing infrastructure provider used across multiple NFT marketplaces and collections, which explains why the exploit affected assets from hundreds of owners across different collections.
The Payment Processor V2 contract on Ethereum and the V3 contract on ApeChain were both implicated. 0xQuit recommended that users revoke approvals on both contracts, specifically directing them to use tools such as Revoke.cash to remove the relevant permissions. The Cryptotimes reported on September 25, 2026, that Revoke.cash now serves as a live checker for the affected contracts.
The vulnerability's presence in a payment processor rather than a marketplace explains the broad impact. Payment processor contracts hold approvals from users across multiple platforms. A flaw in such a contract gives attackers a single point of access to assets spread across the ecosystem.
Limit Break Payment Processor V2 Is The Root Cause
Limit Break Payment Processor V2 was identified as the vulnerable contract. The processor handles payment flows for NFT transactions, meaning it holds transfer approvals from users who have interacted with marketplaces using Limit Break infrastructure. A vulnerability in this contract allows an attacker to execute transfers without the owner's explicit consent for each transaction.
The V3 contract on ApeChain represents a separate deployment of the same payment processing logic. ApeChain is the Layer 2 network associated with the ApeCoin ecosystem and Yuga Labs projects. The presence of the vulnerability on both Ethereum and ApeChain suggests the flaw existed in the shared codebase rather than a single deployment error.
Revoke.cash Becomes The Live Checker
Revoke.cash, a token approval management tool, was deployed as a live checker for the affected contracts. Users can connect their wallets to Revoke.cash to see whether they have active approvals on Payment Processor V2 or V3 and revoke them. The Cryptotimes reported that Revoke.cash lists $0 value approvals that still pose risk, since the vulnerability allows attackers to exploit approvals regardless of the approved amount.
The recommendation to revoke approvals is the standard response to payment processor vulnerabilities. Unlike a marketplace hack where users simply stop using the platform, a payment processor vulnerability requires active user action to remove permissions. Users who do not revoke remain exposed even after the white-hat rescue.
Return Process For 23,155 Rescued NFTs Still Unconfirmed
The return process for the 23,155 rescued NFTs remains unconfirmed as of the latest available information. 0xQuit said the NFTs will be returned to their original owners once the risk is resolved, but no specific timeline or mechanism has been announced. The June 2026 Flooring Protocol rescue provides a precedent: Yuga Labs said the rescued NFTs would be returned once Flooring Protocol developers completed a patch, according to Zoomex reporting.
The scale of Friday's rescue complicates the return process. Returning 23,155 NFTs to hundreds of owners requires either a batch transfer mechanism or individual transactions. Each return must be verified against ownership records to ensure the right NFT goes to the right wallet. This is a non-trivial operational challenge even for a well-resourced team.
The 0x71cF address currently holds the assets. The security of this address is critical during the interim period. If the address were compromised, the rescue would become a theft. The white-hat team has not disclosed what security measures protect the custody address.
The June 2026 Precedent Suggests A Patch-First Approach
The Flooring Protocol rescue from June 8, 2026 followed a patch-first approach. Yuga Labs said the rescued NFTs would be returned once Flooring Protocol developers completed a patch. This suggests Friday's rescue will follow a similar pattern: patch the vulnerability, verify the fix, then return assets.
The patch timeline for Limit Break Payment Processor V2 has not been announced. Until the patch is deployed and verified, returning NFTs to their original wallets would simply re-expose them to the same vulnerability. The white-hat team is likely waiting for confirmation that the exploit vector is closed.
No Formal Restitution Mechanism Announced
Neither Yuga Labs, Magic Eden, nor Limit Break has announced a formal restitution mechanism for the rescued NFTs. The 660 WETH that was not recovered represents a separate loss that may require compensation from the vulnerable protocol or its insurers. No statement has addressed whether the unrecovered WETH will be reimbursed.
The absence of a formal process creates uncertainty for affected owners. They can see their NFTs at the 0x71cF address but cannot access them. The longer the return process takes, the more pressure will build on the white-hat team to provide a concrete timeline.
Market Reaction To The $5.7M NFT Rescue On Friday
The market reaction to the rescue was measured, with no immediate crash in affected collection floor prices. The Cryptonomist's September 25 report noted that Solana's NFT trading volume dropped 5% on Magic Eden in a prior security incident, suggesting that NFT markets typically absorb security events without catastrophic price movements. The rescue itself, by preventing a mass liquidation of stolen NFTs, likely prevented a more severe market disruption.
The 23,155 NFTs secured by the white-hat team represent supply that did not hit the market. If attackers had successfully drained these NFTs and sold them, the resulting supply shock could have depressed floor prices across multiple collections. The rescue prevented this outcome, though the market has not priced in any premium for the successful intervention.
The 660 WETH loss represents actual value extracted from the ecosystem. At the time of the incident, this was a meaningful but not catastrophic loss relative to the $5.7 million in NFTs that were saved. The market's muted reaction suggests traders view the rescue as a net positive for NFT market stability.
No Immediate Floor Price Collapse Observed
No immediate floor price collapse was observed in the affected collections following the rescue. This is consistent with the pattern from the June 2026 Flooring Protocol incident, where white-hat recovery of $500,000 in blue-chip NFTs prevented a broader sell-off. The market appears to have priced in the rescue as a successful defense rather than a sign of systemic weakness.
The absence of panic selling suggests NFT holders have developed some resilience to security incidents. The frequency of exploits in 2026 has conditioned the market to distinguish between active theft and successful defense. Friday's rescue fell into the latter category.
The Watch Item Is The Return Timeline
The next concrete signal for the market is the return timeline for the 23,155 rescued NFTs. If returns begin promptly after the patch is deployed, confidence in the rescue will be reinforced. If returns are delayed or complicated by disputes over ownership, the market may begin to discount the value of the rescued assets.
The base case is that returns proceed once Limit Break patches the vulnerability and the fix is verified. The bull case is that the rescue becomes a template for faster white-hat responses across NFT infrastructure, reducing the expected cost of future exploits. The bear case is that the 660 WETH loss signals a broader vulnerability in payment processor contracts that could be exploited again before patches are fully deployed.
Disclaimer: The content provided on Onebullex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct your own research and consult with a qualified financial advisor before making any investment decisions.















