Zero-price transfers of non-fungible tokens (NFTs) were flagged on Ethereum on Friday, September 25, 2026, after a vulnerability in Limit Break’s Payment Processor marketplace contracts was used first by an unidentified third party and then by a white-hat team, meaning ethical hackers working to move exposed tokens into safe custody.
Security monitors, on-chain records, and the white-hat operators have published different figures because each measured a different phase of the same incident. This report was updated at 10:39 UTC after Blockaid removed its original incident thread. Revoke.cash is now the live public checker of record.
According to the white-hat operator, 23,155 NFTs were relocated for safekeeping, and 660 Wrapped Ether (WETH) was lost before it could be protected. Limit Break had not published an incident statement as of 10:39 Coordinated Universal Time (UTC), and the root cause of the bug remains undisclosed. Those two figures remain Quit’s unaudited claims; Revoke.cash still listed $0 confirmed stolen and 3,832 zero-ETH transfers on its incident page.
What Is Limit Break Payment Processor?
Payment Processor is an NFT exchange protocol built for ERC-721-C and ERC-1155-C tokens, Limit Break’s royalty-enforcing versions of the ERC-721 and ERC-1155 NFT standards, with backward compatibility for standard assets, according to its public code repository. Limit Break describes it as a royalty-enforcing counterpart to protocols such as Seaport and Blur.
The Ethereum V2 deployment is verified on Etherscan, the Ethereum block explorer, as “Limit Break: Payment Processor (V2),” with 63,126 transactions and a zero ETH balance at the time of review.
The contract’s reach traces back to Magic Eden. The NFT marketplace said on February 12, 2024, that its then-upcoming Ethereum marketplace would be powered by Payment Processor. On February 27, 2026, Magic Eden said it would sunset its Ethereum Virtual Machine (EVM) and Bitcoin marketplaces on March 9, 2026, part of Magic Eden’s exit from Bitcoin and EVM NFT trading.
Closing the website did not clear operator approvals that users had already granted on-chain. An operator approval is a blockchain permission, set per NFT collection, that allows a named contract to transfer any token the wallet holds in that collection until the owner revokes it.
How the Zero-Price Transfers Were First Spotted
At 06:31:42 UTC, NFT researcher Cirrus posted that wallet 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 had pulled 3,832 NFTs from hundreds of wallets. Cirrus said the wallet’s funding path appeared linked to Quit, Vice President (VP) of Blockchain at Yuga Labs, the company behind Bored Ape Yacht Club (BAYC), and advised holders to revoke NFT permissions.
Four minutes later, Cirrus added that the transfers were displaying as Magic Eden sales. At 07:05:42 UTC, Cirrus named the revoke target as Payment Processor V2 at 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834.
Quit replied at 06:47:59 UTC: “hey ya this is a whitehat and everything in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 is safe and will be returned once they are no longer at risk.” The post had 1,057 likes and more than 116,000 views by 09:30 UTC.
Quit’s Account: A Malicious Drain, Then an Overnight Rescue
In a thread published at 09:06:00 UTC, Quit set out the sequence he said he reconstructed after being contacted more than 12 hours after the first abuse. He wrote that at 9:00 a.m. Eastern Time (ET), a third party used a bug in Payment Processor V2 to take 10 Meebits, 50 Otherdeeds, 10 World of Women tokens, and 235 Desperate ApeWives.
Quit said he then contacted Limit Break, and the team paused Payment Processor V3, which he said carried the same bug. V2 on Ethereum was not pausable. V3 on ApeChain, the blockchain network tied to the ApeCoin and Yuga Labs ecosystem, was also temporarily unpausable, so approved ApeChain inventory was moved as well.
In the same thread, Quit put the rescue at 23,155 NFTs valued at more than $5.7 million, relocated and held for return after owners revoke the vulnerable approvals. He credited @Boomskite for flagging the first exploit transaction, and @coffeedev, @0xjustadev and @whiteoakkong for recovery work.
Quit also said a related path could be used in reverse against WETH, the ERC-20 token version of Ether commonly used for NFT bids. He said 660 WETH was at risk and was not recovered in time. At 09:15:26 UTC, he wrote that he had worked through the night to save about $6 million of NFTs and was left thinking about “the $1.7M in WETH I wasn’t fast enough for.”
Both WETH figures are Quit’s statements. Neither Limit Break nor an independent forensic firm had published a transaction-level WETH loss table as of 10:39 UTC.
Revoke.cash Replaces the Deleted Blockaid Alert
At 09:11:39 UTC, Revoke.cash posted that Limit Break’s Payment Processor had a known vulnerability and that wallets which traded on Magic Eden’s former Ethereum marketplace likely still approve that contract.
The firm published an incident checker and, one second later, said the exploit “was whitehat-hacked by @0xQuit so it appears that your NFTs are safe,” while still telling holders to revoke remaining approvals.
Revoke.cash’s incident page lists $0 stolen, 3,832 NFTs moved as 0 ETH sales, a reported value of about $1.4 million, and says the tokens sit in a custody wallet that 0xQuit has pledged to return once they are no longer at risk. It also says the bug has not been disclosed and that it is not yet clear whether any NFTs were taken by a malicious actor.
An earlier Blockaid thread that described an ongoing Limit Break exploit, about $1.7 million in NFTs drained across about three transactions, and a list of “exploiter” addresses is no longer available on Blockaid. That $1.7 million figure survives only in secondary recaps posted before the whitehat explanation was widely cited, and it should not be treated as Blockaid’s current public statement.
One later Blockaid post, still live at 08:26:13 UTC, tells users who approved Payment Processor V2 as an NFT operator to revoke that approval. The spender named in that post is 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834. Blockaid added that canceling listings or a master nonce does not remove the operator grant. If a wallet never approved this contract, it is not on this path.
The figure of roughly $1.7 million now appears in three leftover contexts, none of them a live Blockaid post: deleted-alert reprints that treated early NFT transfers as theft, Quit’s dollar value for the 660 WETH, and an NFTScan valuation of the rescue wallet. None of these measure the same assets. Some early reprints of the Blockaid alert treated $1.7 million as stolen NFT value while the whitehat explanation was still emerging.
What the Sample Transaction Shows On-Chain
Etherscan shows the transaction previously cited in the deleted Blockaid thread as successful in block 26,052,469 at 05:46:47 UTC on September 25, 2026. The sender is the rescue wallet. The value is 0 ETH, the fee is 0.001287876307204188 ETH, and gas used is 7,770,918 of a 9,657,644 limit at 0.165730266 gwei.
All NFTs in that single transaction went to the rescue wallet: 16 BAYC tokens (IDs 6841, 1086, 511, 5707, 4026, 4948, 6673, 9410, 7218, 2912, 2930, 8037, 6325, 1106, 7859 and 1858), three Art Blocks tokens (IDs 694, 9288 and 9592) and Winds of Yawanawa token 768.
The logs include AcceptOfferERC721 events from Payment Processor V2. The recorded buyer is 0x415F981b474b2E060D314BEc14461d9aeEf70B1a, the beneficiary is the rescue wallet, the payment coin is WETH (0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2), and the sale price is zero. Twenty NonceInvalidated events, covering order nonces 0 to 19, were emitted with wasCancellation set to False. A nonce is a one-time order number that prevents the same signed order from being filled twice.
This is an event-level description of what settled, not a root-cause analysis. Limit Break and Quit have not published a line-by-line explanation, and Revoke.cash states that the precise vulnerability has not been disclosed.
Rescue Wallet Holdings
Etherscan shows the rescue wallet holding 0.740686352159854733 ETH and a broad book of NFTs, including Art Blocks (166), Opepen Edition (227), Nakamigos (113), 0N1 Force (58), HV-MTL (78), Invisible Friends 3D (66), a KID called BEAST (91), Cool Cats (42) and Creepz (53), plus smaller lots across BAYC-adjacent collections, World of Women, Beanz and others.
NFTScan’s live page for the same address showed 8,472 NFTs across 447 collections with an estimated value of $1,723,844.31 at the time of the query, while inbound transfers were still arriving. The gap with Quit’s 23,155-token total may reflect ApeChain holdings and tokens not yet indexed. Neither figure is a closed forensic inventory.
The third address, previously listed in the deleted Blockaid thread, 0xB48..1C8E, is a contract tagged TrustedForwarder on Etherscan. It shows no external transactions and one internal creation from 0xFF0000B6c4352714cCe809000d0cd30A0E0c8DcE in block 26,052,371. It should not be labeled an exploiter address.
Which Wallets Are Exposed
Quit’s 08:09:39 UTC alert, restated at 09:06:01 UTC, named two contracts to revoke:
- Ethereum Payment Processor V2: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834
- ApeChain Payment Processor V3: 0x9a1D00000000fC540e2000560054812452eB5366
Revoke.cash published an incident checker at 09:11:39 UTC, warning that wallets that traded on Magic Eden’s former Ethereum marketplace may still approve Payment Processor V2. The page recorded 3,832 NFTs moved as 0 ETH sales and said it was not yet clear whether any tokens were taken by a malicious actor. As of 10:39 UTC, that page still lists $0 stolen and has not adopted Quit’s later 23,155-NFT and 660 WETH totals.
Exposure is not limited to former Magic Eden users. Atomist.eth pointed to documented integrations including Mintify’s prior V2 integration and Otherside marketplace documentation listing the ApeChain V3 address. Risk depends on which contract a wallet approved, including through an aggregator, and disconnecting a wallet from a website does not revoke an on-chain operator grant.
What NFT Holders Should Do Now
- Check every wallet that listed or bid through Magic Eden’s former Ethereum marketplace, Mintify, Otherside, or ApeChain Payment Processor integrations, or any other Payment Processor front end.
- Revoke operator approval for both contracts listed above through Revoke.cash or an equivalent approval manager, and wait for on-chain confirmation. Revoke.cash and Blockaid’s remaining 08:26 UTC post both warn that canceling a listing or rotating a marketplace nonce is not sufficient.
- If tokens now sit in the rescue wallet, treat Quit’s statement as the current custody claim and wait for a published return process. Revoke first, since returning an NFT to a wallet that still grants the same approval would recreate the exposure.
- Ignore unsolicited recovery messages, claim sites, and “support” wallets. Neither Limit Break nor Quit had posted an official claim contract as of 10:39 UTC.
Official Statements Still Pending
As of 10:39 UTC, Limit Break’s main X account had not posted an incident statement; its latest post reviewed was an April 15, 2026 mobile-game test announcement. Quit’s statement that V3 was paused remains his account until Limit Break publishes its own confirmation. Blockaid has not replaced the deleted alert with a corrected incident thread.
At 10:44 UTC, @MagicEden issued an interim update. It said Payment Processor V2 is a Limit Break protocol that Magic Eden adopted to settle EVM trades in 2024. Magic Eden said it stopped using V2 in October 2024, shut its EVM marketplace in Q1 2026, and that no live Magic Eden listings were hit. It thanked @0xQuit for the whitehat rescue and said it is contacting Limit Break, the owner and maintainer, about further mitigations, including pausing transfers on the protocol. The company said its investigation is still open.
Several points remain unconfirmed: a public postmortem of the V2 and V3 bug; a signed Limit Break incident report with V3 pause transaction hashes; an ApeChain inventory matching the 23,155-token total; a transaction-level schedule of the 660 WETH loss; and an independent reconciliation of the deleted Blockaid reprints, NFTScan, Revoke.cash, and Quit figures. It is also unclear whether tokens taken in the first malicious window beyond the four collections Quit named have been sold or moved further.
Figures in this report are attributed to the source that produced them and were current at the times stated. NFT valuations based on floor prices move with the market. This report will be updated when Limit Break or an independent monitor publishes transaction-level data.
Also Read: Magic Eden Ethereum Flaw: Whitehat 0xQuit Secures 3,832 NFTs, Users Told to Revoke Approvals
