An exploit in Limit Break’s Payment Processor V2 resulted in the theft of NFTs until security experts uncovered the flaw and initiated a whitehat recovery operation. This update comes from 0xQuit, who is also known as Quit, the anonymous vice president of blockchain at Yuga Labs.

At 9 AM EST today, an individual took advantage of a vulnerability in Payment Processor V2, stealing 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate Apewives.

It was not until over 12 hours later that I received a report about this issue. Upon investigation, I discovered that a significant number of NFTs were at risk of being compromised… pic.twitter.com/Vue8TUyMD2

— Quit (@0xQuit) September 25, 2026

As outlined by Quit, the initial breach affected 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate ApeWives. Further analysis revealed that a larger number of NFTs were also exposed to this vulnerability.

In response, Limit Break swiftly halted Payment Processor V3 after being notified, but V2 could not be deactivated, necessitating the transfer of compromised assets through a whitehat operation.

Additional vulnerabilities were identified on ApeChain, where assets approved for V3 needed safeguarding. Overall, 23,155 NFTs valued at over $5.7 million were successfully recovered, while a related exploit that could potentially drain WETH left 660 WETH exposed and unrecovered.

Magic Eden indicated that it ceased using Payment Processor V2 in October 2024 and closed its EVM marketplace in early 2026, assuring that no active Magic Eden listings were impacted.

The platform warned that NFTs listed on its EVM site between roughly February and October 2024 might still be at risk and advised users to revoke specific “approved for all” permissions.

Share.