Whitehats rescue $5.7M in NFTs after Limit Break exploit

Editorial illustration: A white robotic arm lifts colorful framed artworks from a cracked dark vault toward a cream storage tray. Crystal Ethereum symbols remain on the vault’s bottom shelf, with rubble scattered below.

In brief

  • Limit Break Payment Processor V2 bug enabled theft of high-value NFTs including Meebits, Otherdeeds, and World of Women
  • Whitehats recovered 23,155 NFTs valued at $5.7 million in coordinated security operation
  • Related WETH vulnerability on ApeChain left additional assets at risk

The Rescue Operation

In total, 23,155 NFTs worth more than $5.7 million were rescued through the coordinated whitehat effort. The exploit's reach extended beyond the initial collections, affecting a broad range of assets across multiple platforms.

Limit Break quickly paused Payment Processor V3 after being alerted to the vulnerability. However, Payment Processor V2 could not be paused, requiring affected assets to be moved through a whitehat operation. This architectural limitation forced security researchers to manually secure compromised holdings rather than simply disabling the vulnerable contract.

Broader Exposure and Unrecovered Assets

A similar vulnerability was also found on ApeChain, where some assets approved to V3 needed to be secured. The cross-chain nature of the exposure underscored how payment processor vulnerabilities can cascade across multiple blockchain networks.

Not all assets were recovered. A related exploit that could be used to steal WETH left 660 WETH at risk and unrecovered.

Magic Eden's Exposure

Magic Eden said it stopped using Payment Processor V2 in October 2024, placing the marketplace ahead of the exploit's discovery. No live Magic Eden listings were affected by the attack.

However, historical exposure remains a concern. NFTs listed on its EVM platform between approximately February and October 2024 may still be exposed. Magic Eden shut down its EVM marketplace in the first quarter of 2026, eliminating future risk from that vector.