White Hat Operation Rescues 23K NFTs After Payment Processor Exploit

1 hour ago 1



Holders whose NFTs moved without their permission are being told to revoke old contract approvals before any rescued tokens get sent back. On September 25, a wallet linked to pseudonymous security researcher Quit pulled 3,832 NFTs out of hundreds of unrelated wallets, the first visible sign of a rescue operation built around a bug in LimitBreak’s Payment Processor V2 contract. The operation eventually relocated 23,155 NFTs worth nearly $6 million, while a separate exploit path left 660 WETH unrecovered. White Hat Operation Moves Thousands of NFTs The incident first drew attention when NFT trader Cirrus reported that a wallet had drained 3,832 NFTs from more than 100 wallets. Quit, who is also the VP of Blockchain at Yuga Labs, later confirmed that the transfers were part of a white-hat operation. “Everything in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 is safe and will be returned once they are no longer at risk,” the researcher wrote. They explained that the underlying issue involved Payment Processor V2. At 9 a.m. EST, an attacker used the bug to take 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Despertae Apewives. Quit then found that many other NFTs were exposed ...

Read Entire Article