The NFT marketplace says outdated smart contract approvals left $5.7 million in assets exposed, and has published a process for owners to reclaim rescued NFTs.
Magic Eden has confirmed that an exploit tied to outdated smart contract approvals compromised user assets on its platform. The company said legacy approval permissions, left active from earlier versions of its marketplace contracts, exposed about $5.7 million worth of NFTs to unauthorized access.
Of that exposure, attackers were able to extract roughly $1.8 million in wrapped Ether, according to Magic Eden. Wrapped Ether, or wETH, is commonly used across NFT marketplaces to facilitate trades without requiring native ETH transactions for every listing or purchase.
Approval-based exploits are a recurring risk in NFT and token trading. When a user lists an item or interacts with a marketplace contract, they often grant that contract standing permission to move specific assets on their behalf. If a contract is later deprecated or a vulnerability is discovered, those old permissions can remain active. Attackers who identify unrevoked legacy approvals can use them to transfer assets without needing further authorization from the wallet owner.
Magic Eden said some of the affected NFTs were rescued during the incident, meaning they were moved out of harm's way before being fully drained by the exploit. The company has since published guidance describing how eligible users can verify whether their assets were part of this rescue effort and how to initiate the process of reclaiming them.
The distinction between assets that were rescued and assets that were lost outright appears central to how affected users should respond. Those whose NFTs were rescued may be able to recover them directly through Magic Eden's stated process. Those whose wETH or NFTs were fully removed by the attacker face a different, and likely more difficult, recovery path.
The incident adds to a long list of exploits across crypto trading platforms that trace back to approval management rather than a compromise of private keys or custody infrastructure. Security researchers have repeatedly urged users to periodically review and revoke smart contract approvals, particularly on marketplaces they no longer actively use. Wallet interfaces and third-party tools exist specifically to audit outstanding approvals, though many users do not routinely check them.
Magic Eden has not detailed the exact number of individual wallets affected, nor the specific mechanism by which the legacy approvals were first exploited. The reported figures on total exposure and losses come directly from the company's own disclosures following the incident.
The exploit is unlikely to move broader NFT market pricing given the relatively contained dollar figures involved, but it reinforces scrutiny of marketplace security practices at a time when NFT trading volumes remain well below their earlier peaks. Platforms that fail to sunset old contract permissions cleanly risk both direct financial exposure and reputational damage among traders who already view NFT infrastructure with caution.
For Magic Eden specifically, how it handles the recovery process for rescued assets, and any compensation discussion for those whose wETH was fully lost, could influence user trust and trading activity on the platform in the near term. The episode also serves as a reminder to the wider industry that approval hygiene remains a persistent, addressable risk across NFT and token marketplaces.
Magic Eden's disclosure highlights how legacy technical debt, rather than a single dramatic hack, can quietly expose significant user value over time. Affected users are advised to follow the marketplace's published recovery guidance and to review approvals on other platforms as a precaution.
Magic Eden said the incident stemmed from outdated legacy smart contract approvals that remained active and allowed unauthorized transfers of user assets.
Magic Eden reported that legacy approvals exposed about $5.7 million in NFTs, with attackers extracting roughly $1.8 million worth of wrapped Ether.
Rescued NFTs are assets that were moved to safety during the incident before an attacker could fully remove them, and Magic Eden has outlined a process for owners to reclaim these items.
Users are generally advised to periodically review and revoke smart contract approvals, especially for marketplaces or applications they no longer actively use.
Bitwise NEAR ETF Cleared for NYSE Arca Listing, NEAR Token Price Jumps
Regulators Accuse Cash FX Group of Running $950M Crypto-Tied Forex Fraud
Bitcoin Consolidates Near $84K as Traders Watch for Volatility Breakout
Ripple CEO Says XRP Isn’t Always the Right Tool for Every Payment
September 27, 2026
September 26, 2026
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect