White-hat researchers moved tens of thousands of NFTs to safety after a long-dormant settlement contract was used to pull tokens from wallets that still carried old marketplace permissions. The issue involved Limit Break’s Payment Processor V2, a contract that once handled on-chain settlement for Magic Eden’s Ethereum NFT venue.
Magic Eden stopped using that processor in October 2024 and later shut its EVM marketplace.
The allowances users granted at the time did not vanish with the product.
Wallets that had listed or settled trades still had operator approval sitting on-chain.On the morning of September 25, 2026, an attacker abused a flaw in V2 to take NFTs as if they were being sold for nothing.
The first wave included 10 Meebits, 50 Otherdeeds, 10 World of Women pieces, and 235 Desperate ApeWives.
More than twelve hours passed before the activity was reported to 0xQuit, vice president of blockchain at Yuga Labs.
After reviewing the contract, he concluded that a far larger set of tokens faced the same risk.
Limit Break paused Payment Processor V3, which shared the weakness.
V2 could not be paused.
The only workable defense was a coordinated rescue: move exposed NFTs before hostile actors reached them.
A similar problem on ApeChain, where V3 could not be paused at the time, required the same treatment for assets approved there.
The operation recovered 23,155 NFTs valued at more than $5.7 million. Researchers later found the same logic could be inverted to drain wrapped ether.
About 660 WETH was at risk and could not be saved in time.
At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives.
It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the… pic.twitter.com/Vue8TUyMD2
— Quit (@0xQuit) September 25, 2026
Quit publicly apologized to those holders.
On-chain observers first saw thousands of tokens leaving wallets at a listed price of zero ETH and assumed a mass theft.
Quit identified the receiving address as a protective custody wallet and said the tokens would be returned once they were no longer exposed. Owners must revoke the vulnerable approvals first.
Returning an NFT while the old permission remains active would put it back in reach of the same contract.
Magic Eden has said no live listings on its current systems were involved and has urged former EVM users to revoke Payment Processor V2 allowances on Ethereum and other chains where the old marketplace operated.
The episode is a blunt case of leftover approvals outliving the product that requested them.
Marketplace shutdowns do not cancel on-chain operator rights.
Those rights last until a holder revokes them.
The processor was built as a general settlement layer for ERC-721 and ERC-1155 trades, including Limit Break’s creator-token standards.
That breadth made unused approvals unusually dangerous years after the frontend disappeared.
White-hat speed limited the NFT losses. The unrecovered ether and the manual revoke-and-claim process that followed show how expensive forgotten permissions can still become.