0x1f9003311f90…1f90032e
Magic Eden Investigates Possible Exploit as NFTs Move for Zero ETH
Magic Eden is investigating a possible exploit after listed NFTs sold for 0 ETH, leaving sellers unpaid; the scope, affected collections and root cause remain undetermined.

Outputs
Magic Eden is investigating a possible exploit after NFTs moved for 0 ETH.
Sellers received no payment while listed NFTs changed hands in valid on-chain transfers.
The company has not disclosed the number of affected NFTs, the chains involved, or a timeline for findings.
Magic Eden, the multi-chain NFT marketplace, is investigating a possible exploit on its platform after users reported that NFTs listed for sale moved out of their wallets in transactions executed for 0 ETH, according to the company's public statements and on-chain records flagged by collectors.
The incident came to light when multiple NFT owners reported that items listed on Magic Eden — including pieces from well-known collections — were purchased for zero Ether, meaning the sellers received no payment while their assets changed hands. The affected transactions appear on-chain as valid transfers, which suggests the exploit, if confirmed, targeted the marketplace's listing or order-matching infrastructure rather than the underlying blockchain itself.
Magic Eden confirmed it is investigating the reports. The marketplace has not yet published a full technical post-mortem, and it remains unclear how many NFTs were affected, which collections bore the brunt of the losses, or whether the flaw sat in Magic Eden's own order book, in a third-party integration, or in how signed listing approvals were handled.
Zero-price sales of this kind typically point to one of a few failure modes. An attacker may have found a way to invalidate or circumvent a listing's price at execution, exploited a mismatch between an off-chain order and its on-chain settlement, or abused an approval granted to a marketplace contract. On Ethereum-mainnet-style architectures, listings are frequently signed messages executed against an exchange contract; if the contract fails to rigorously enforce the price embedded in the signed order, a buyer can fill it at an arbitrary value — including zero.
Magic Eden operates across multiple chains, including Solana, Ethereum, and Bitcoin via its ordinals and runes offerings, and its cross-chain order infrastructure broadens the surface area its engineers must audit. The company has not said which chain or listing standard the suspicious transfers involved, a detail that will matter for rival marketplaces checking whether they share the same vulnerability.
For users, the operational consequence is immediate: NFTs listed on Magic Eden carried execution risk while the investigation was open. Collectors responding to the reports moved to delist their assets, a standard defensive step when a marketplace's matching logic comes under question, since delisting revokes the signed orders that an exploit could target.
The episode also carries business consequences for Magic Eden beyond the immediate losses. Marketplace competition in the NFT sector turns heavily on trust in custody-adjacent infrastructure, and a confirmed exploit in order handling would give competitors an opening to press their own security models. If the investigation establishes that sellers lost assets through no fault of their own, Magic Eden will face pressure to reimburse affected users, as rival platforms have done after past incidents — a cost that scales with the number of zero-value fills recorded on-chain.
The on-chain record gives investigators a concrete trail. Every zero-ETH purchase is a permanent, timestamped transfer, so the full scope of the incident — wallets involved, collections affected, and total value taken — can be reconstructed from chain data even before the company publishes its own accounting. That transparency cuts both ways: it makes scope concealment difficult, and it lets third-party analysts verify or challenge Magic Eden's eventual findings.
Users who listed NFTs on Magic Eden during the exposure window should check their wallet activity for unexpected transfers, revoke active listing approvals where their wallet setup allows it, and watch for an official incident report before relisting. Marketplace-specific approvals generally can be managed through the platform's own settings or through token-approval tooling on the relevant chain.
Magic Eden has not announced a timeline for completing the investigation or a reimbursement decision. The company's next disclosures — the root-cause determination and any remediation and compensation plan — will determine whether this remains a contained technical incident or becomes a lasting reputational liability for one of the highest-volume NFT marketplaces still operating.
via Google News - Crypto Hack Exploit (Source)