Tag: NFT exploit

  • Whitehats Rescue $5.7 Million in NFTs After Limit Break Payment Processor Exploit

    Whitehats Rescue $5.7 Million in NFTs After Limit Break Payment Processor Exploit

    Key Highlights

    • Limit Break’s Payment Processor V2 was exploited at 9 AM EST on September 25, 2026, resulting in the theft of 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives before a whitehat operation rescued 23,155 NFTs valued at over $5.7 million.
    • The vulnerability extended to ApeChain assets approved to Payment Processor V3, while a related exploit left 660 WETH at risk and unrecovered.
    • Magic Eden confirmed it discontinued Payment Processor V2 in October 2024 and shut down its EVM marketplace in Q1 2026, stating no live listings were affected, but urged users who listed NFTs between February and October 2024 to revoke “approved for all” permissions.

    Exploit Discovery and Initial Impact

    The security incident came to light through a public disclosure by 0xQuit, known publicly as Quit, the pseudonymous vice president of blockchain at Yuga Labs. In a post on X at 9 AM EST on September 25, 2026, Quit detailed the attack timeline:

    At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives.
    It wasn’t until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the…

    According to Quit, the exploit remained undetected for more than 12 hours before being reported. Upon investigation, researchers determined that the vulnerability affected a far broader set of NFT collections than initially compromised. The stolen assets included high-profile collections: Meebits, Otherdeeds (Otherside metaverse land deeds), World of Women (referenced as “WoW” in the tweet), and Desperate ApeWives.

    Whitehat Rescue Operation and Scope of Vulnerability

    Limit Break responded by immediately pausing Payment Processor V3 after being alerted to the vulnerability. However, Payment Processor V2 could not be paused due to its architectural design, necessitating a whitehat rescue operation to move affected assets to safety. The operation ultimately secured 23,155 NFTs with a combined value exceeding $5.7 million.

    The investigation revealed that a similar vulnerability existed on ApeChain, where some assets that had approved Payment Processor V3 also required emergency securing. Additionally, researchers identified a related exploit vector that could be used to steal WETH (Wrapped Ether). As of the disclosure, 660 WETH remained at risk and had not been recovered.

    Magic Eden’s Response and User Guidance

    Magic Eden issued a statement clarifying its exposure to the vulnerability. The marketplace confirmed it stopped using Payment Processor V2 in October 2024 and subsequently shut down its EVM marketplace in the first quarter of 2026. The company emphasized that no live Magic Eden listings were affected by the exploit.

    However, Magic Eden warned that NFTs listed on its EVM platform between approximately February and October 2024 may still be exposed to the vulnerability. The marketplace urged affected users to revoke “approved for all” permissions granted during that period to mitigate ongoing risk.

    Why This Matters

    This incident underscores persistent smart contract risks in NFT infrastructure, particularly in permissioned approval systems like “setApprovalForAll” that grant broad spending authority. The fact that Payment Processor V2 could not be paused highlights a critical design limitation in upgradeable contract architectures where older versions remain immutable and operational. The 12-hour detection gap also reveals monitoring gaps in high-value asset protocols. With 660 WETH still at risk from a related vector, the situation remains active. Marketplaces like Magic Eden discontinuing legacy processors reduces surface area, but historical approvals create long-tail exposure requiring user action. The cross-chain impact on ApeChain demonstrates how shared infrastructure vulnerabilities can cascade across ecosystems.

    Frequently Asked Questions

    Which NFT collections were initially stolen in the Payment Processor V2 exploit?

    The initial theft involved 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives, as reported by 0xQuit (Quit) of Yuga Labs.

    Can users still protect assets that were listed on Magic Eden’s EVM marketplace in 2024?

    Yes. Magic Eden advises users who listed NFTs on its EVM platform between approximately February and October 2024 to revoke any “approved for all” permissions granted during that period to mitigate exposure.

    What is the status of the 660 WETH at risk from the related exploit?

    As of the disclosure, the 660 WETH remains at risk and has not been recovered. The related exploit vector is distinct from the primary Payment Processor V2 vulnerability but was identified during the same investigation.