# malicious approval — X 热门讨论 (2026-09-26 06:56 UTC)

## @wyckoffweb (wyck 📴) · 09-25 08:52 · ♥90 ↻5 💬20 Someone just moved 3,832 NFTs out of hundreds of people's wallets without those people signing a new transaction.

And apparently, they did it to save them.

NFT trader Cirrus noticed thousands of NFTs suddenly leaving wallets for 0 ETH.

The wallets weren't being individually hacked.

The owners had previously given Magic Eden's marketplace contracts permission to move their NFTs.

Those approvals were still active.

So if the approved contract had a vulnerability, someone could potentially use that old permission to move the NFTs without asking the owner to approve another transaction.

One wallet managed to pull 3,832 NFTs from hundreds of wallets.

Then people noticed something strange.

The wallet appeared connected to 0xQuit, VP of Blockchain at Yuga Labs.

He confirmed he was behind it and said it was a whitehat operation.

The NFTs weren't being stolen.

They were being moved before someone malicious could apparently do the same thing.

He says everything sitting in the rescue wallet is safe and will be returned once the risk is gone.

But this is the part worth paying attention to.

Magic Eden shut down support for its EVM NFT marketplace back in March.

That doesn't automatically remove permissions people gave its contracts while using it.

You can stop using a dApp.

Forget you ever used it.

And months later, the approval you gave it can still be sitting inside your wallet.

This time a whitehat got there first.

How many old contracts still have permission to move things from your wallet?

You've got to stay safe. https://x.com/wyckoffweb/status/2103407313474248779