BLOCKCHAIN AI.NEWS

Security

23,155 NFTs Rescued From a Contract Nobody Could Pause

People who listed NFTs on Magic Eden's Ethereum marketplace in 2024 had given Limit Break's Payment Processor V2 permission to move them, and that permission never expired. This week someone found a bug in the contract. It has no off switch, so a whitehat emptied the exposed wallets before the attacker could. A reverse version of the same bug took WETH, and nobody got to that in time.

Editorial illustration: a chrome turnstile with a blue key still in its lock, and a long line of frosted glass tiles running through it down a glass corridor toward a gold-lit doorway
✓ Drain first flagged by Cirrus on X · Rescue account by 0xQuit · Statement from Magic Eden · On-chain analysis by CryptoTicker · Timeline by The Crypto Times · One WETH transaction verified by the Desk against an Ethereum node

At 06:31 UTC on September 25, an NFT account called Cirrus posted that it had just watched one wallet pull 3,832 NFTs out of hundreds of other people's wallets. "No idea whats going on here," it wrote, adding that the wallet seemed to be funded from an address "possibly linked to @0xQuit so maybe a whitehat?"

Sixteen minutes later, 0xQuit, a security researcher who is Yuga Labs' VP of blockchain, replied that it was. Everything in the receiving address, 0x71cF…fe33, was "safe and will be returned once they are no longer at risk."

At 09:06 UTC he explained why. Somebody had "abused a bug in Payment Processor V2" to take 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives, and "it wasn't until over 12 hours later that somebody reported it to me." When he looked, he found many more NFTs exposed to the same flaw. Limit Break, which built the contract, paused Payment Processor V3, which he said had the same bug. "Unfortunately, V2 was not pausable, so the only path towards protecting affected assets was to run a whitehat operation." V3 on ApeChain was temporarily in a state where it couldn't be paused either, so assets approved to it were moved too.

His tally was 23,155 NFTs, "worth north of $5.7M USD." Then: "We later discovered that a similar exploit could be used in reverse to steal WETH. 660 WETH was at risk, which we unfortunately were not fast enough to recover."

Why Magic Eden is in the story

Payment Processor V2 is a Limit Break contract, not a Magic Eden one. Magic Eden's interim update at 10:44 UTC made that point early. The company said it "adopted" the protocol to settle EVM trades in 2024, stopped using V2 in October 2024 and shut its EVM marketplace altogether in the first quarter of 2026. "No live Magic Eden listings were impacted," it said. That is true, and it does not help much, because the listings were never the problem.

The problem is how an NFT marketplace works. To list an NFT, you usually sign an "approve for all" permission that lets a settlement contract move any token from that collection out of your wallet when a sale clears. To make a WETH offer, you usually approve the contract to spend your WETH. Neither permission expires. Taking down a listing, closing a marketplace or switching settlement contracts doesn't change what the old contract is still allowed to do. Magic Eden said NFTs listed on its EVM marketplace between roughly February and October 2024 "could be impacted." Revoke.cash put it more bluntly in its warning, as reported by CryptoSlate: "Canceling a listing will not protect an exposed wallet."

So the exposure was nearly two years of approvals that nobody had cleaned up, pointed at a contract that couldn't be stopped. Neither Limit Break nor anyone else has published what the bug actually was. The on-chain evidence shows what it did.

What one transaction shows

CryptoTicker read every trade event Payment Processor V2 emitted on Ethereum between September 23 at 12:00 UTC and September 25 at 12:22 UTC, blocks 26,040,040 to 26,054,436. It dated the first attack to 13:08 UTC on September 24, which is 9:08 a.m. Eastern and matches Quit's "9AM" timing, and put the start of the WETH drain at 08:25 UTC on September 25. Its explanation of the reverse attack: fresh contracts mint worthless dummy NFTs, and Payment Processor V2 is made to "buy" them on behalf of victim wallets, paying with WETH those wallets had approved when they placed offers.

The Desk checked the example transaction CryptoTicker cited, 0xdd3a…a96b, against a public Ethereum node. It is a single contract-creation transaction in block 26,053,260, timestamped 08:26:11 UTC on September 25. Its logs include events from Payment Processor V2 at 0x9A1D…6834 and from the WETH token. It moves WETH from 25 separate wallets, between 3.5 and 29.39 WETH each, into an intermediate contract at 0x860b…9c8d, which then sends 281.66 WETH on to the address that sent the transaction. That is about 43 percent of Quit's 660 WETH, from one transaction, in one block.

The Desk has not linked that sending address to any person or group, and it is not the rescue address.

The counts don't agree yet

FigureValueSource
NFTs taken in the first malicious transfers3050xQuit
NFTs seen leaving wallets, first sighting3,832Cirrus
NFTs rescued, total23,155 (>$5.7M)0xQuit
Assets listed on the reclaim site26,448Cryptopolitan
WETH lost, all chains6600xQuit
WETH drained on Ethereum to Sep 25, 12:22 UTC530.7 from 911 walletsCryptoTicker
WETH in one transaction281.66 from 25 walletsDesk, block 26,053,260
Sources: 0xQuit, Cirrus, Cryptopolitan, CryptoTicker. CryptoTicker's WETH count covers Ethereum only and stops at its read window; Quit's covers everything. Neither is a final loss figure.

The gaps have plausible explanations. CryptoTicker's count covers Ethereum only and stops at 12:22 UTC, and it says the attack was still running at 12:40 UTC on September 26. Cryptopolitan puts the malicious haul at "at least $2.8 million" across five chains: Ethereum, Polygon, Base, Arbitrum and ApeChain. Plausible explanations are not a reconciliation, though, and Limit Break is the party that could provide one.

What Limit Break has and hasn't said

The contract owner has said the least. The Crypto Times noted that Limit Break had published no incident statement as of 10:39 UTC on September 25, and that the pause of V3 was known only from Quit's account, with no transaction hashes. CryptoTicker found no statement by its own deadline either. Magic Eden said it was "contacting Limit Break as they are the owner & maintainer of the protocol" to see what else could be done, "including progress on pausing transfers on the protocol." The Desk found no public post-mortem from Limit Break at publication.

That leaves several questions open. What was the bug? Why was V2, a contract settling NFT trades worth millions, deployed with no way to pause it? And given that a sibling contract on ApeChain was in the same unpausable state, which other Limit Break deployments are too?

What to do if you traded there

Magic Eden and Quit gave the same instructions. Anyone who listed or traded on Magic Eden's EVM marketplace should go to revoke.cash and remove every "approved for all" permission granted to Payment Processor V2 at 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 on Ethereum, Polygon and Base, and to V3 at 0x9a1D00000000fC540e2000560054812452eB5366 on ApeChain, per Quit's address list. WETH allowances to the same contracts should go too. As Magic Eden said, revoking "does not return tokens that already moved."

Cryptopolitan reports that a reclaim site is live, that owners must revoke the V2 approval before claiming, and that 2,357 of 26,448 assets had been claimed when it checked. A rescue like this attracts impersonators, and fake claim portals are the obvious next attack. Get the claim link from Quit's own X account, not from a reply, a DM or a news site, this one included.

The Take

Quit and the people who helped him did the only thing available, did it overnight, and are giving the NFTs back. That deserves credit without qualification. It also shows what went missing. The only thing protecting 23,155 NFTs was one researcher happening to be told about the bug twelve hours late. A settlement contract that can move other people's assets needs a working off switch, and the company that owns it should be the first to explain a failure, not the last. For everyone else: an approval is a standing order, and a marketplace closing doesn't cancel it. Two years is a long time to leave one open.

More on the subject