
A vulnerability in the Payment Processor V2 allowed the unauthorized transfer of thousands of NFTs, initially wrongly attributed to Magic Eden.
AI-generated summary
The flaw exploited smart contract authorizations left active by users after third-party services were closed. Limit Break's Payment Processor V2 was at the heart of the vulnerability.
Magic Eden designated too quickly. Thousands of NFTs have left their wallets through an old contract formerly integrated into its EVM marketplace. However, the flaw came from Limit Break's Payment Processor V2, which an attacker had already started to exploit when 0xQuit, vice-president of blockchain at Yuga Labs, launched a rescue operation.
The white hat has secured 23,155 NFTs valued at over $5.7 million. On the other hand, around 660 WETH, or almost $1.7 million, could not be recovered at this point. Here's what we know.
Key Points
The vulnerability concerned the Payment Processor V2 of Limit Break, formerly integrated by Magic Eden
0xQuit secured 23,155 NFTs valued at over $5.7 million
An attacker had already started exploiting the flaw and around 660 WETH was not recovered
Affected holders must revoke their authorizations on Ethereum V2 and ApeChain V3 contracts
Magic Eden singled out, an old flaw at Limit Break
The first movements immediately attracted attention. Thousands of NFTs left hundreds of wallets through transactions displayed as sales at 0 ETH, always heading to the same address. As explorers associated these operations with Magic Eden, the marketplace found itself at the center of suspicion.
However, the vulnerability belonged to the Payment Processor V2 of Limit Break, an NFT sales protocol formerly integrated by Magic Eden in order to enforce creator royalties. The platform stopped using this version in October 2024, before closing its EVM market on March 9, 2026. Announcements, offers and auctions then disappeared from its interface, without removing the authorizations granted directly on the blockchains.
An attacker had already used the flaw when the Yuga Labs team identified the problem. Early stolen assets included Meebits, Otherdeeds, World of Women and Desperate ApeWives.
0xQuit and Limit Break then launched a rescue operation. An initial observation reported 3,832 NFTs moved, but the final toll reached 23,155 NFTs, valued at more than $5.7 million. They have been consolidated to the same next address and 0xQuit ensures that they are safe and can be returned after revoking vulnerable permissions.
Limit Break: Old approvals exposed NFT and WETH
To function, the Payment Processor had to obtain authorization to move the NFTs offered for sale. However, an approval given to a smart contract generally remains active until its revocation, even when the service that used it closes or changes protocol.
This flaw allowed an attacker to present themselves as the holder of an NFT still covered by this authorization, then to trigger its transfer for 0 ETH. No listing still visible on Magic Eden was necessary: the approval left in the wallet was sufficient to maintain exposure.
The team also discovered that a reverse variant could target WETH, the tokenized ether notably used to place bids on NFTs. Around 660 WETH were thus exposed and could not be recovered during the rescue operation. 0xQuit estimates the loss at nearly $1.7 million, but further recovery cannot yet be ruled out.
The Payment Processor V3 deployed on ApeChain presented a comparable weakness. Limit Break was able to suspend this version, unlike the Ethereum V2 contract, which remained accessible due to its decentralized operation.
0xQuit recommends removing permissions granted to the following two addresses:
Ethereum V2: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834
ApeChain V3: 0x9a1D00000000fC540e2000560054812452eB5366
This operation can be done using a tool like revoke.cash. It does not automatically bring back assets already moved, but prevents the contract concerned from transferring new ones.
AI outlook — possibilities, not facts
Return of 23,155 secure NFTs after revocation of authorizations.
Likely · Within weeks

The L2BEAT platform has introduced a new section evaluating crypto privacy protocols according to five adversary profiles. This technical approach aims to clarify the real guarantees of data protection in the face of regulatory pressure.

The Services and Payment Agency confirms a data leak via fraudulent access to a user account on August 27, 2026, detected the next day. More than 143,000 people would be affected according to FrenchBreaches, with 2023-2024 payment notices from the Île-de-France “Coup de Pouce Energie” system containing names, addresses, IBAN/BIC, beneficiary numbers and amounts paid. This is the second such leak at ASP in five months.

China opened an investigation in late September 2026 into DeepSeek and Moonshot AI after Anthropic's accusations of allegedly using fraudulent accounts to train their models on Claude's responses. CAC investigators are seeking to determine whether sensitive Chinese data was transferred to U.S. servers, rather than focusing on alleged technological theft to the detriment of Anthropic.

Ukraine's Ministry of Digital Transformation gains access to Daybreak, OpenAI's cybersecurity tool powered by GPT-5.6 Sol, to audit its aging infrastructure in the face of Russian attacks.

Cardano joins the x402 protocol, enabling automated payments for AI agents and online services. The official TypeScript kit now supports ADA and native tokens, although usage is currently limited to the staging network.

More than 52 bitcoins from the Coldcard wallet hack were transferred to a legal trust in Wyoming to be returned to their owners, after being sheltered by ethical hackers.