White hats rescue 23,155 NFTs worth $5.7 million following Limit Break contract vulnerability
A vulnerability in Limit Break's Payment Processor V2 linked to legacy Magic Eden approvals prompted a white-hat rescue of 23,155 NFTs valued at over $5.7 million, while roughly 660 WETH was lost.

A white-hat operation moved 23,155 NFTs valued at more than $5.7 million to safety after a vulnerability was discovered in Limit Break's Payment Processor V2, a contract previously used by Magic Eden's Ethereum marketplace. Although Magic Eden ended support for its EVM marketplace in March, previously granted approvals remained active on-chain, exposing holders to zero-ETH asset transfers.[2][3][4][5][6]
According to Yuga Labs VP of Blockchain 0xQuit, an attacker initially exploited the flaw on Sept. 25, 2026, to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives. After user Boomskite flagged the transaction hours later, 0xQuit coordinated an emergency response with developers coffeedev, 0xjustadev, and whiteoakkong. Limit Break quickly paused Payment Processor V3, but V2 could not be paused and ApeChain V3 could not be paused temporarily, requiring a white-hat sweep. A reverse variant of the exploit put 660 WETH at risk, which was not recovered.[4][5]
The rescued NFTs were moved to protective custody—with early transfers routed to an address beginning with 0x71cF—and will be returned once owners revoke exploitable permissions. Holders were urged to immediately revoke approvals to Payment Processor V2 on Ethereum and Payment Processor V3 on ApeChain.[1][5][6][7]
Key facts
- A white-hat operation rescued 23,155 NFTs worth more than $5.7 million following an exploit of Limit Break's Payment Processor V2.
- The exposure was enabled by active on-chain approvals remaining from Magic Eden's former Ethereum marketplace.
- An attacker stole 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives in an initial exploit of the contract.
- Approximately 660 WETH, valued at roughly $1.7 million, was lost through a reverse version of the exploit and was not recovered.
- Limit Break paused Payment Processor V3, but Payment Processor V2 on Ethereum could not be paused.
- Rescued NFTs are being held safely and will be returned to owners after they revoke the vulnerable approvals.
- Holders were urged to revoke approvals to Payment Processor V2 on Ethereum and Payment Processor V3 on ApeChain.
Sources · 7 sources
- WB
Wu Blockchain@WuBlockchainPost on X ·
Magic Eden Suspected of NFT Security Vulnerability as White Hat Moves 3,832 NFTs NFT marketplace Magic Eden is suspected of having a security vulnerability after a white hat moved 3,832 NFTs from hundreds of wallets. Yuga Labs CEO Michael Figge said the issue was discovered hours earlier and that Yuga Labs VP of Blockchain Quit (0xQuit) is handling affected assets within the scope of the white-hat rescue. Quit said the NFTs are currently secured at an address beginning with 0x71cF and will be returned to their original owners once the risk is resolved. Magic Eden has not yet disclosed the cause or full scope of the issue.
Open source - DE
DecryptArticle ·
Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit A flaw in Limit Break's Payment Processor V2 put old Magic Eden Ethereum listings at risk, prompting a whitehat rescue of more than 23,000 NFTs.
Open source - CO
CoinMarketCap@CoinMarketCapPost on X ·
LATEST: 🚨 Magic Eden says legacy EVM approvals exposed over $5.7M in NFTs to an exploit against Limit Break's Payment Processor V2, though a whitehat operation was able to rescue 23,155 NFTs. https://t.co/Rk5bqsnwZo
Open source - CP
Crypto Patel@CryptoPatelPost on X ·
MAGIC EDEN NFT SECURITY INCIDENT: $5.7M IN NFTs EXPOSED A major NFT security incident has hit the ecosystem after a vulnerability was discovered in Limit Break’s Payment Processor V2, a contract previously used by Magic Eden’s Ethereum marketplace. The critical issue: old NFT approvals remained active on-chain even after @MagicEden stopped using the system. 🔹 23,155 NFTs reportedly rescued 🔹 Estimated value: $5.7M+ 🔹 NFTs were moved to safety through a white-hat rescue 🔹 ~660 WETH reportedly remained unrecovered, worth roughly $1.7M at the cited valuation Important: This was NOT simply a $5.7M Magic Eden hack. The $5.7M figure represents NFTs that were potentially exposed and subsequently rescued. Users should review and revoke outdated NFT contract approvals if they interacted with affected contracts.
Open source - QU
Quit@0xQuitPost on X ·
At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives. It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the same exploit. I got in touch with the team over at LimitBreak and they quickly paused Payment Processor V3, which was subject to the same exploit. Unfortunately, V2 was not pausable, so the only path towards protecting affected assets was to run a whitehat operation. Similarly, V3 on ApeChain is temporarily in a state where it cannot be paused, so ApeChain assets approved to V3 needed to be saved as well. All in all, we rescued 23,155 NFTs worth north of $5.7M USD. We later discovered that a similar exploit could be used in reverse to steal WETH. 660 WETH was at risk, which we unfortunately were not fast enough to recover. Apologies to those affected. Shout out to @Boomskite for flagging the initial exploit tx to me, and @coffeedev @0xjustadev and @whiteoakkong for acting quickly and assisting with the recovery. All NFTs are safely relocated. Soon, owners will be able claim them back after revoking the exploitable approvals. Addresses to revoke below.
Open source - W�
wyck 📴@wyckoffwebPost on X ·
Someone just moved 3,832 NFTs out of hundreds of people's wallets without those people signing a new transaction. And apparently, they did it to save them. NFT trader Cirrus noticed thousands of NFTs suddenly leaving wallets for 0 ETH. The wallets weren't being individually hacked. The owners had previously given Magic Eden's marketplace contracts permission to move their NFTs. Those approvals were still active. So if the approved contract had a vulnerability, someone could potentially use that old permission to move the NFTs without asking the owner to approve another transaction. One wallet managed to pull 3,832 NFTs from hundreds of wallets. Then people noticed something strange. The wallet appeared connected to 0xQuit, VP of Blockchain at Yuga Labs. He confirmed he was behind it and said it was a whitehat operation. The NFTs weren't being stolen. They were being moved before someone malicious could apparently do the same thing. He says everything sitting in the rescue wallet is safe and will be returned once the risk is gone. But this is the part worth paying attention to. Magic Eden shut down support for its EVM NFT marketplace back in March. That doesn't automatically remove permissions people gave its contracts while using it. You can stop using a dApp. Forget you ever used it. And months later, the approval you gave it can still be sitting inside your wallet. This time a whitehat got there first. How many old contracts still have permission to move things from your wallet? You've got to stay safe.
Open source - DN
DEGEN NEWS@DegenerateNewsPost on X ·
NEW: @yugalabs' @0xQuit CLAIMS WHITEHAT RESCUE AFTER THOUSANDS OF NFTS WORTH MILLIONS WERE MOVED FROM HUNDREDS OF WALLETS TO A SAFE WALLET @0xQuit ASKS NFT ENTHUSIASTS TO REVOKE APPROVALS TO THESE PAYMENT PROCESSOR V2 ON ETHEREUM: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 PAYMENT PROCESSOR V3 ON APECHAIN: 0x9a1D00000000fC540e2000560054812452eB5366
Open source

