The site for owners to recover their NFTs has gone live, according to the whitehat that launched the rescue mission to save at-risk NFTs during the security incident where 2024-era Magic Eden users were exposed due to an exploit of Limit Break’s Payment Processor.
Part of the conditions for owners to reclaim their NFTs, according to 0xQuit, the vice president of blockchain researcher at Yuga Labs, who ran the rescue mission, is that they first revoke the old, problematic approval.
The recovery process is entirely free as well, with only standard gas fees applied.

Notably, only rescued NFTs can be reclaimed from the site, while those in possession of the exploiters are not recoverable, as of this Cryptopolitan report.
0xQuit declared the recovery site open late on Saturday, writing on X, “Claim site is live. If I was able to save your NFTs, you can now reclaim them,” he wrote on X.
To avoid repeat exposure, the Yuga Labs executive warned that NFT owners can only reclaim their NFTs after they revoke the Payment Processor approval that caused the whole incident in the first place.
Revoke.cash also warned that the attack relies only on the approval, so canceling listings is ineffective at stopping the exploit.
nftsaresafu.xyz is the only official site, and as of publication, 2,357 have already been claimed out of the 26,448 recovered assets.
0xQuit also warned that the claim interacts with a delegated wallet setup, which can interfere with transaction simulation in some wallets.
The September 2026 exploit has roots that go back as far as an NFT trading protocol that Magic Eden adopted in 2024 to settle EVM trades, Payment Processor V2. However, according to Revoke.cash, when Magic Eden dropped the processor built by Limit Break in October 2024, the token and NFT approvals users granted during that period were never turned off on-chain.
That active permission was what the attacker exploited, using it to hijack NFTs outright and to buy worthless NFTs using tokens stored in wallets.
At least $2.8 million has been stolen since the exploit began on September 24, affecting wallets on Ethereum, Polygon, Base, Arbitrum, and ApeChain.
Because V2 cannot be paused or patched, it stays vulnerable indefinitely. Limit Break paused the newer V3 everywhere except ApeChain, where it stays usable until November 30, 2026.
0xQuit said the attack surfaced after someone abused the bug to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives, and that it took more than 12 hours before anyone flagged it to him.
Once he grasped the scope, security researchers used the same flaw defensively to move at-risk assets into a wallet under their control. The operation reportedly rescued 23,155 NFTs worth more than $5.7 million.
Not everything could be reached in time. “660 WETH was at risk, which we unfortunately were not fast enough to recover,” 0xQuit told The Block, explaining that the exploit could be run in reverse to pull WETH.
Some collections will not release cleanly. 0xQuit warned that holders of ERC721C or ERC1155C collections may be unable to claim because of transfer validator rules, and asked affected collection owners to adjust their settings or allowlist the site. He said he would work through those cases over the coming days.
Magic Eden said no live listings were hit and that it closed its EVM marketplace in the first quarter of 2026. The marketplace advised users to revoke the V2 approval on Ethereum, Polygon, and Base. Meanwhile, OpenSea co-founder Chris Maddern said his team had flagged more than 3,000 items as stolen to block resale.
Events like this draw scammers. Cryptopolitan has previously reported that fake “recovery” and “claim” sites tend to follow high-profile exploits, so users should reach the claim tool only through 0xQuit’s verified post and revoke approvals through a trusted checker rather than links sent by strangers in DMs or replies.
The smartest crypto minds already read our newsletter. Want in? Join them.