Reports: Limit Break Contract Exploit Drains Suspected 660 WETH Before NFT Rescue

CIE News ·

Security researchers are monitoring a suspected exploit targeting the Payment Processor V2 smart contract, an infrastructure component developed by Limit Break and historically integrated by NFT marketplace Magic Eden. According to preliminary on-chain data and reports from security analysts, attackers reportedly exploited a critical logic vulnerability that allowed them to siphon an estimated 660 WETH and illicitly transfer hundreds of non-fungible tokens. As the incident unfolded, white-hat security researcher 0xQuit reportedly stepped in to secure approximately 23,155 at-risk NFTs, valued at an estimated $5.7 million, transferring the digital assets into protective custody across multiple blockchain networks to prevent further potential drainage.

Initial post-mortem analyses suggest the attack leveraged lingering smart contract approvals, specifically persisting setApprovalForAll permissions that users had previously granted to the Payment Processor V2 contract. Attackers allegedly bypassed standard payment requirements by taking advantage of a flaw in the contract logic, enabling them to acquire the approved NFTs for 0 ETH. Because permissions on Ethereum-compatible blockchains remain active indefinitely until manually revoked, user holdings on networks including Ethereum, Polygon, and Base appeared vulnerable even where historical marketplace interfaces or integrations were no longer active.

While investigations into the developing incident remain active and total damages continue to be assessed, security specialists are urging users who interacted with the affected contracts to immediately revoke historical permissions using tools like Revoke.cash. Affected holders whose tokens were relocated by white-hat interveners are expected to receive further instructions on secure asset retrieval procedures. Analysts emphasize that unrevoked legacy allowances continue to pose significant systemic risks across the ecosystem as long as dormant contract authorizations persist.