White-hat researchers have completed one of the largest rescue operations in NFT history, moving 23,155 NFTs worth more than 5.7 million USD out of harm’s way after a flaw in a long-retired payment contract was exploited on September 25. The twist: the vulnerable contract had not been used in almost two years — but the permissions users granted it never expired.
By Jordan Lee | September 28, 2026
The Hook: An Old Door Nobody Locked
Here is what happened, according to Crowdfund Insider. The flaw sat in Limit Break’s Payment Processor V2, a contract that once handled on-chain settlement for Magic Eden’s Ethereum NFT marketplace. Magic Eden stopped using that processor in October 2024 and later shut its EVM marketplace entirely. The problem: the allowances users had granted did not vanish with the product. Wallets that had listed or settled trades back then still had standing approvals attached to the old contract — like giving a house-sitter a key and never asking for it back.
On the morning of September 25, an attacker abused the V2 flaw to take NFTs as if they were being sold for nothing. The first wave included 10 Meebits, 50 Otherdeeds, 10 World of Women pieces, and 235 Desperate ApeWives — collections tied closely to the Yuga Labs ecosystem.
The Rescue: Racing the Attackers to the Vault
What turned an exploit into a rescue operation was speed. More than twelve hours passed before the activity was reported to 0xQuit, vice president of blockchain at Yuga Labs. Once he reviewed the contract, the picture got much worse: a far larger set of tokens carried the same risk.
Limit Break paused its newer Payment Processor V3, which shared the weakness. But V2 could not be paused — the old contract had no kill switch. That left only one defense: move every exposed NFT to safety before hostile actors reached them. White-hat researchers swept through affected wallets, ultimately securing 23,155 NFTs valued at more than 5.7 million USD. A similar exposure on ApeChain, where V3 could not be paused at the time, got the same emergency treatment.
- 23,155 NFTs — recovered by white hats, worth more than 5.7 million USD
- 10 Meebits, 50 Otherdeeds, 10 World of Women, 235 Desperate ApeWives — the first wave taken by the attacker on September 25
- 660 WETH — wrapped ether that was at risk and could not be saved in time, after researchers found the same flaw logic could be inverted to drain it
- October 2024 — when Magic Eden stopped using the vulnerable V2 processor
The Core Conflict: Old Approvals Never Die
The uncomfortable lesson here applies far beyond Magic Eden. In crypto, a permission you grant today can sit dormant for years and still work perfectly when someone finally abuses it. The NFT community has been burned by this before — the lesson after every similar incident is the same: revoke old approvals. Tools exist that let any wallet owner list and cancel the permissions they have handed to marketplace contracts over the years. Most people never check.
There is also a governance question. Why could V2 not be paused? Older contracts were often deployed without upgradeability or emergency stops — a deliberate design choice (“code is law”) that trades flexibility for immutability. When things go wrong, immutability means the only fix is a race against attackers. Newer contracts, like V3, included a pause function — and that difference is exactly why the rescue was even possible.
Market Implications: What It Means for Your Wallet
If you have ever listed an NFT on a marketplace — especially one you stopped using years ago — this story is about you. The single most useful action you can take today is to run an approval-revocation tool on your wallet and clean out permissions you no longer need. It costs a few small transaction fees and removes an entire category of risk.
For the wider NFT market, the incident cuts both ways. The loss of 660 WETH and the first wave of stolen NFTs shows the space’s scars have not healed. But the rescue itself — thousands of tokens saved by coordinated researchers within hours — shows the defensive side of the ecosystem has genuinely leveled up. Blue-chip collections with active security teams, like those in the Yuga orbit, now have faster incident response than many traditional firms.
The Verdict
This was a near-miss turned into a save. A dormant contract from 2024 nearly emptied collections worth millions, and only a rapid white-hat response kept the damage contained. The takeaway for every collector is boring but vital: old approvals are live ammunition. Revoke them. And when you choose marketplaces and contracts in the future, favor the ones with a pause button — because the day you need it, there is no second chance.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
white hats racing attackers to save 23k nfts is the best content crypto produced all year. 660 weth still gone tho, rip
Standing approvals from that old Magic Eden processor sitting dormant since 2024 are the scary part. Check your wallets people.
saved 50 otherdeeds and 235 desperate apewives but lost 660 weth. honestly a decent trade all things considered lol
660 weth gone and calling it a decent trade tells you how low the bar is. white hats did hero work, the approval system still failed everyone
contract retired for two years and the approvals still work. this is why i go on a revoke spree every month now lol
^ exactly, i did the same after this news. 23k NFTs relocated in hours is some serious coordination from the white hats tho, respect
monthly revoke sprees should just be default wallet hygiene at this point. 23k nfts saved proves the coordination works, 660 weth proves the approvals dont expire
0xQuit catching this before the drainer got the rest is the real story. 660 WETH gone but 5.7 million USD in NFTs moved to safety
660 WETH could not be saved is a very polite way of saying someone watched their money leave in real time
approvals from a contract retired back in 2024 still active is the scary part. magic eden moved on years ago and nobody revoked anything