Overview
- Reporters and on‑chain researchers traced the initial abuse of Limit Break’s Payment Processor V2 to the morning of Sept. 24, when an attacker pulled NFTs from approved wallets and sold some for 0 ETH.
- Pseudonymous whitehat 0xQuit worked with Limit Break to move 23,155 vulnerable NFTs, roughly $5.7 million in value, into a custody wallet to prevent wider theft and to hold them until owners revoke approvals.
- Limit Break paused its V3 processor but could not pause V2, so rescuers had to physically relocate assets on‑chain rather than fix the live contract, creating a race between whitehats and malicious actors.
- Security teams and Magic Eden said no active listings were hit but warned that users who listed on Magic Eden’s EVM marketplace from February–October 2024 likely left the V2 approval live and must revoke it on Ethereum, Polygon and Base.
- Investigators found a related attack path that exposed about 660 WETH which was not recovered, and they urged users to check and revoke lingering approvals using tools such as Revoke.cash while the probe continues.