Whitehats rescue $5.7 million in NFTs after Limit Break Payment Processor exploit

A bug in Restrict Break’s Fee Processor V2 was exploited to steal NFTs earlier than safety researchers recognized the difficulty and launched a whitehat rescue operation, as reported by 0xQuit, additionally recognized publicly as Stop, the pseudonymous vice chairman of blockchain at Yuga Labs.
At 9AM EST right now anyone abused a bug in Fee Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Determined Apewives.
It wasn’t till over 12 hours later that anyone reported it to me, and upon digging in I noticed that an important many NFTs had been topic to the… pic.twitter.com/Vue8TUyMD2
— Stop (@0xQuit) September 25, 2026
In keeping with Stop, the exploit initially affected 10 Meebits, 50 Otherdeeds, 10 World of Girls NFTs and 235 Determined ApeWives, earlier than researchers decided that many extra NFTs had been weak to the identical assault.
Restrict Break rapidly paused Fee Processor V3 after being alerted, however V2 couldn’t be paused, requiring affected property to be moved by way of a whitehat operation.
The same vulnerability was additionally discovered on ApeChain, the place some property authorised to V3 wanted to be secured. In whole, 23,155 NFTs price greater than $5.7 million had been rescued, whereas a associated exploit that might be used to steal WETH left 660 WETH in danger and unrecovered.
Magic Eden stated it stopped utilizing Fee Processor V2 in October 2024 and shut down its EVM market within the first quarter of 2026, including that no dwell Magic Eden listings had been affected.
{The marketplace} stated NFTs listed on its EVM platform between roughly February and October 2024 should be uncovered and urged customers to revoke affected “authorised for all” permissions.





