Cryptelio

Hacks & Exploits

Whitehat Team Rescues $5.7 Million in NFTs Following Limit Break Payment Processor Exploit

Cryptelio Editorial Published 25 Sep 2026 · 18:15 UTC

In a significant security operation, whitehat researchers have rescued 23,155 non-fungible tokens (NFTs) valued at more than $5.7 million following a bug in Limit Break’s Payment Processor V2. The incident was reported by 0xQuit, the vice president of blockchain at Yuga Labs, who detailed how an attacker exploited the vulnerability to steal various NFTs, including Meebits and Otherdeeds.

The exploit occurred early in the morning, with the first thefts going unnoticed for over 12 hours. Upon investigation, 0xQuit discovered that many more NFTs were at risk due to the same flaw. Although Limit Break paused Payment Processor V3, the older V2 version remained active, necessitating a proactive whitehat rescue operation to secure the vulnerable NFTs.

In total, the operation successfully relocated 23,155 NFTs to safety. However, the investigation also revealed that around 660 Wrapped Ether (WETH) was exposed, but the whitehat team was unable to recover those funds. The rescued NFTs are currently held in a custody wallet and will be returned to their owners once they revoke the vulnerable contract approvals.

Limit Break’s Payment Processor V2 serves as an on-chain settlement layer for NFT marketplaces, supporting various token standards. Magic Eden, which previously adopted this protocol, confirmed that it ceased using V2 in October 2024, although lingering approvals could still pose risks to former users.

Revoke.cash has issued warnings to users regarding old NFT approvals, emphasizing the need to revoke permissions granted to Payment Processor V2 and V3 on ApeChain to mitigate potential risks.

FAQ

What happened in the Limit Break Payment Processor exploit?

A vulnerability in Limit Break's Payment Processor V2 was exploited, leading to the theft of various NFTs valued at over $5.7 million. Whitehat researchers intervened to rescue 23,155 NFTs that were at risk.

Who reported the exploit and what was their role?

The exploit was reported by 0xQuit, the vice president of blockchain at Yuga Labs, who detailed the attack and the subsequent rescue operation.

What types of NFTs were stolen during the exploit?

The stolen NFTs included various types, notably Meebits and Otherdeeds, among others.

What is the current status of the rescued NFTs?

The rescued NFTs are currently held in a custody wallet and will be returned to their owners once they revoke the vulnerable contract approvals.

What precautions should users take regarding old NFT approvals?

Users are advised to revoke permissions granted to Payment Processor V2 and V3 on ApeChain to mitigate potential risks, as lingering approvals could still pose security threats.

Read story →