Limit Break Payment Processor Exploit
Attackers abused a flaw in Limit Break's Payment Processor NFT contract — still holding stale approvals from Magic Eden users — to drain tokens and NFTs worth at least $2.8 million across five chains.
- Date
- Victim
- Limit Break
- Status
- Funds Stolen
On September 24, 2026, attackers began exploiting a flaw in Limit Break's Payment Processor — an NFT-trading contract that thousands of wallets had approved back when Magic Eden used it — to steal tokens and NFTs worth at least $2.8 million across five chains.
What happened
Payment Processor is an NFT settlement contract built by Limit Break. Magic Eden routed marketplace trades through it in 2024, so a large number of users granted it approval to move their NFTs and ERC-20 tokens such as WETH. Magic Eden stopped using it in October 2024, but those approvals were never revoked and stayed live. On September 24, 2026, attackers began abusing a flaw in the older Payment Processor V2 that let them act on behalf of any wallet still holding an approval — taking NFTs for free and draining approved tokens by forcing wallets to "buy" worthless NFTs. Thefts were spread across Ethereum, Polygon, Base, Arbitrum, and ApeChain and were still ongoing as researchers raised the alarm, with stolen value put at $2.8 million or more.
Aftermath
Because Payment Processor V2 cannot be paused or upgraded, it remains permanently vulnerable — the only real defense is for users to revoke the stale approval. Limit Break paused the newer V3 on every chain except ApeChain, where it was left usable until November 30, 2026. In a notable rescue, security researchers led by 0xQuit of Yuga Labs turned the same flaw against the attackers, moving over 23,000 at-risk NFTs worth more than $5.7 million into a safe wallet for owners to reclaim. The tokens and NFTs actually taken by the attackers were not recovered, so the status here is stolen.
Why it matters
Token approvals are a standing liability: an approval granted to a contract in 2024 is still a loaded gun in 2026 if it is never revoked and the contract is later found flawed. As with approval-drainer campaigns like the repeat whale phishing drain, the safest posture is to treat every unused approval as attack surface and revoke it — an immutable contract cannot be fixed after the fact.
Sources & on-chain evidence
- [01]revoke.cashhttps://revoke.cash/exploits/magic-eden?chainId=1
- [02]cryptoticker.iohttps://cryptoticker.io/en/magic-eden-limit-break-exploit-weth-nfts-revoke-approvals/
- [03]phemex.comhttps://phemex.com/news/article/limit-break-exploit-on-ethereum-drains-17m-in-nfts-via-payment-processor-v2-flaw-97828