MultiversX Tracker is Live!

Whitehat hacker, 0xQuit, rescues 23,155 NFTs (~$5.7M) from a live exploit in an old Limit Break contract that Magic Eden stopped using in 2024.

All Cryptocurrencies

by COINS NEWS 11 Views

A bug in an NFT payment contract got exploited yesterday, and the only reason it didn't turn into a much bigger disaster is before the attacker could get to them, 0xQuit moved 23,155 NFTs to his own wallet. He promised to return them once the wallets had revoked approvals. The contract is Limit Break's Payment Processor V2, which Magic Eden used on its Ethereum marketplace in 2024.

What happened

At 9AM ET on Sept 24, someone found a hole in a contract most people forgot existed. Limit Break's Payment Processor V2 settled NFT trades on Magic Eden's Ethereum marketplace back in 2024, and the bug let an attacker act as the holder of any NFT approved to it & take it for 0 ETH. The first pulls were 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives.

Nobody raised the alarm for over 12 hours, and there wasn't much reason to be watching. Magic Eden stopped using Payment Processor V2 in October 2024 and shut down its EVM marketplace completely in Q1 2026. Anyone who listed an NFT there between February and October 2024 most likely gave the contract "approve for all" on that collection, and those approvals didn't go anywhere when the marketplace did. A dead contract on a dead marketplace still had permission to move more than 23,000 NFTs.

Then, whitehat hacker 0xQuit discovered this and realized a huge number of NFTs were exposed to the same bug. Payment Processor V3 on ApeChain had a similar issue, and Limit Break paused it. V2 couldn't be paused, so the only way to protect everything still sitting behind an old approval was to get there first. The whitehat & the Limit Break team ran a rescue and moved the exposed NFTs into a safe wallet before the attacker could take them.

Around 2:30AM ET, NFT trader Cirrus noticed thousands of NFTs leaving hundreds of wallets for 0 ETH, about 3,832 by his estimate. He read it the way anyone would, as a drain, and told everyone to revoke their approvals. Quit replied: "hey ya this is a whitehat and everything in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 is safe and will be returned once they are no longer at risk."

His recap:

All in all, we rescued 23,155 NFTs worth north of $5.7M USD.

We later discovered that a similar exploit could be used in reverse to steal WETH. 660 WETH was at risk, which we unfortunately were not fast enough to recover. Apologies to those affected.

And his post after the all-nighter:

worked through the entire night to save ~$6M worth of NFTs and all I'll be able to think about is the $1.7M in WETH I wasn't fast enough for.

Fuck scammers.

Approvals don't expire

Magic Eden stopped using Payment Processor V2 in October 2024 and shut down its EVM marketplace entirely in Q1 2026. None of that touched the approvals. If you listed an NFT on Magic Eden's EVM marketplace between February and October 2024, you probably gave that contract "approve for all" on the collection, and that approval was still live yesterday, almost two years after Magic Eden moved on.

That's the whole lesson here. When you list an NFT, you usually approve the marketplace's contract to move every NFT you hold in that collection, and that permission sits there until you revoke it. The platform can deprecate the contract, shut down the marketplace & rebrand, and your approval stays live the entire time. Most people never go back and clean them up, which is how these exploits keep finding victims years after anyone last used the contract.

There's also a lesson on immutable contracts. V2 couldn't be paused, which is great until the day it has a bug. On that day the only defense is a whitehat racing the attacker, and yesterday the whitehat won on the NFTs and lost on the WETH.

So who's Quit?

0xQuit is the VP of Blockchain at Yuga Labs (Bored Apes, Mutant Apes, Otherside, CryptoPunks & Meebits). This is his second rescue this year. In June he led a whitehat operation during the Flooring Protocol exploit that pulled 68 NFTs out of vulnerable pools, including 29 Bored Apes & 2 CryptoPunks, worth over $500K. He's a legend in the NFT space.

Security hygiene reminder

  1. Go to revoke[.]cash.
  2. Revoke every "approve for all" to Limit Break: Payment Processor (V2) on Ethereum, Polygon and Base. That's Magic Eden's own guidance. The Ethereum address is 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834.
  3. If you used ApeChain, revoke the Payment Processor there too: 0x9a1D00000000fC540e2000560054812452eB5366.
  4. If your NFTs got moved to 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33, that's Quit's safe wallet. Revoke first, since he's returning assets once they're no longer at risk, and only trust updates from 0xQuit directly. Anyone DMing you about "recovering" your NFTs is a scammer
  5. And don't be a dummy, while you're there, revoke everything you don't actively use.

Shout out to 0xQuit and the Limit Break team for the all-nighter.

submitted by /u/TimmyXBT
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
πŸ’° Install these recommended apps:
πŸ’² SocialGood - 100% Crypto Back on Everyday Shopping
πŸ’² xPortal - The DeFi For The Next Billion
πŸ’² CryptoTab Browser - Lightweight, fast, and ready to mine!
πŸ’° Register on these recommended exchanges:
🟑 Binance🟑 Bitfinex🟑 Bitmart🟑 Bittrex🟑 Bitget
🟑 CoinEx🟑 Crypto.com🟑 Gate.io🟑 Huobi🟑 Kucoin.



Comments