Whitehats rescue $5.7 million in NFTs after Limit Break Payment Processor exploit

Shutterstock cover by mundissima

Whitehats rescue $5.7 million in NFTs after Limit Break Payment Processor exploit

Magic Eden advised users who had listed or traded NFTs on its former EVM marketplace to revoke the Payment Processor V2 contract approval and repeat the process on Ethereum, Polygon and Base.

Whitehat researchers have rescued 23,155 non-fungible tokens valued at more than $5.7 million after a bug in Limit Break’s Payment Processor V2 left a large number of NFTs vulnerable to theft, 0xQuit, also known publicly as Quit, the pseudonymous vice president of blockchain at Yuga Labs, reported Friday.

The operation followed an exploit in which an attacker stole 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate Apewives. 0xQuit said the incident was not reported to him until more than 12 hours after the first attack, when further investigation revealed that many other NFTs were exposed.

After digging into the exploit, 0xQuit determined that a much larger number of NFTs could be targeted through the same flaw and alerted Limit Break. The company quickly paused Payment Processor V3, which was vulnerable to the same issue.

Advertisement

However, V2 could not be paused, meaning affected NFTs had to be proactively moved through a whitehat rescue operation.

A similar vulnerability was also found on ApeChain, where some assets approved to V3 needed to be secured. In total, 23,155 NFTs worth more than $5.7 million were rescued, as noted by 0xQuit.

The investigation also uncovered a related attack path that could be used to steal WETH rather than NFTs. Around 660 WETH was exposed, but the whitehat team was unable to recover those funds.

0xQuit said the rescued NFTs had been relocated safely and that owners would eventually be able to reclaim them after removing vulnerable contract approvals.

Limit Break’s Payment Processor V2 provides an onchain settlement layer for NFT marketplaces and applications, supporting trades involving ERC-721 and ERC-1155 tokens as well as Limit Break’s ERC-721C and ERC-1155C creator-token standards.

In a statement, Magic Eden said it adopted the protocol to settle EVM trades in 2024 but stopped using V2 in October 2024 and ended its EVM marketplace in the first quarter of 2026.

The marketplace said no live listings were affected, although NFTs listed on its EVM marketplace from approximately February to October 2024 could still be exposed through lingering approvals.

According to Magic Eden, users who used its former EVM marketplace should revoke the Payment Processor V2 approval on Ethereum, Polygon and Base, while Limit Break and security researchers continue to investigate the exploit.

Disclosure: This article was edited by Vivian Nguyen. For more information on how we create and review content, see our Editorial Policy.
Whitehats rescue $5.7 million in NFTs after Limit Break Payment Processor exploit
Whitehats rescue $5.7 million in NFTs after Limit Break Payment Processor exploit

Magic Eden advised users who had listed or traded NFTs on its former EVM marketplace to revoke the Payment Processor V2 contract approval and repeat the process on Ethereum, Polygon and Base.

Shutterstock cover by mundissima

Whitehat researchers have rescued 23,155 non-fungible tokens valued at more than $5.7 million after a bug in Limit Break’s Payment Processor V2 left a large number of NFTs vulnerable to theft, 0xQuit, also known publicly as Quit, the pseudonymous vice president of blockchain at Yuga Labs, reported Friday.

The operation followed an exploit in which an attacker stole 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate Apewives. 0xQuit said the incident was not reported to him until more than 12 hours after the first attack, when further investigation revealed that many other NFTs were exposed.

After digging into the exploit, 0xQuit determined that a much larger number of NFTs could be targeted through the same flaw and alerted Limit Break. The company quickly paused Payment Processor V3, which was vulnerable to the same issue.

Advertisement

However, V2 could not be paused, meaning affected NFTs had to be proactively moved through a whitehat rescue operation.

A similar vulnerability was also found on ApeChain, where some assets approved to V3 needed to be secured. In total, 23,155 NFTs worth more than $5.7 million were rescued, as noted by 0xQuit.

The investigation also uncovered a related attack path that could be used to steal WETH rather than NFTs. Around 660 WETH was exposed, but the whitehat team was unable to recover those funds.

0xQuit said the rescued NFTs had been relocated safely and that owners would eventually be able to reclaim them after removing vulnerable contract approvals.

Limit Break’s Payment Processor V2 provides an onchain settlement layer for NFT marketplaces and applications, supporting trades involving ERC-721 and ERC-1155 tokens as well as Limit Break’s ERC-721C and ERC-1155C creator-token standards.

In a statement, Magic Eden said it adopted the protocol to settle EVM trades in 2024 but stopped using V2 in October 2024 and ended its EVM marketplace in the first quarter of 2026.

The marketplace said no live listings were affected, although NFTs listed on its EVM marketplace from approximately February to October 2024 could still be exposed through lingering approvals.

According to Magic Eden, users who used its former EVM marketplace should revoke the Payment Processor V2 approval on Ethereum, Polygon and Base, while Limit Break and security researchers continue to investigate the exploit.

Disclosure: This article was edited by Vivian Nguyen. For more information on how we create and review content, see our Editorial Policy.