Limit Break Payment Processor V2 hack — September 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 25, 2026 |
| Target type | NFT project or marketplace |
| Loss | $2,800,000Price at time of incident |
| Method | Access control flawPayment Processor V2 let a caller execute trades in the name of any wallet that had approved it, taking NFTs through self-accepted zero-price offers and WETH through forced purchases of worthless NFTs; the contract cannot be paused, and no technical write-up has been published |
| Chains | Ethereum, Polygon, Base, Arbitrum, Other |
| Outcome | Unresolved |
What happened
Payment Processor V2, an NFT trading protocol built and maintained by Limit Break, was exploited from 24 September 2026 through approvals that wallet owners had granted it years earlier. Magic Eden used the contract to settle trades on its EVM marketplace between roughly February and October 2024, so its users approved it to move their NFTs and, to make offers, their WETH. Magic Eden stopped using the processor in October 2024 and closed its EVM marketplace in early 2026, but the approvals are on-chain permissions and stayed live until each owner revoked them.
The flaw let an attacker act on behalf of any wallet holding such an approval. For NFTs the attacker accepted its own zero-price offer in the owner's name and took the token for nothing; for WETH it listed a worthless NFT and forced the approving wallet to buy it. The first known thefts, 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate ApeWives, came on the morning of 24 September, US Eastern time, according to 0xQuit, vice president of blockchain at Yuga Labs, and went unreported for more than twelve hours. Revoke.cash puts the NFTs and tokens stolen at no less than $2.8m across Ethereum, Polygon, Base, Arbitrum and ApeChain, with thefts still continuing when it published, and that is the figure recorded here. It includes about 660 WETH, which 0xQuit valued at $1.7m and which is kept as the lower end. Neither Limit Break nor Magic Eden has published a technical account, so the access-control classification follows the behaviour researchers describe rather than a confirmed root cause.
Because V2 cannot be paused or upgraded, the only defence left was to use the flaw first. 0xQuit and other researchers moved at-risk NFTs into a custody wallet through zero-price sales, which the NFT tracker Cirrus flagged early on 25 September as 3,832 NFTs leaving hundreds of wallets; the operation eventually secured 23,155 NFTs worth more than $5.7m. Those assets never reached the attacker and are counted here as neither loss nor recovery. A claim site opened on 26 September, and owners must revoke the old approval before reclaiming. Limit Break paused Payment Processor V3, which shared the flaw, on every chain except ApeChain, where it remains usable until 30 November 2026, and OpenSea said it had flagged more than 3,000 items as stolen to block their resale. Nothing the attacker took has been returned.
Sources
- Revoke.cashSecondary · retrieved 2026-09-27
- DecryptSecondary · retrieved 2026-09-27
- Bitcoin.com NewsSecondary · retrieved 2026-09-27
- CryptopolitanSecondary · retrieved 2026-09-27
- CryptoSlateSecondary · retrieved 2026-09-27
Changes to this entry
- Recorded three days after the first thefts. Provisional: the $2.8m is Revoke.cash's running total, taken while thefts were still under way, and neither Limit Break nor Magic Eden has published a loss figure or a root cause. The 23,155 NFTs moved by the whitehat rescue are not counted as stolen.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Limit Break Payment Processor V2 hack — September 2026", iTokenly, accessed 2026-09-27, https://itokenly.com/hacks/limit-break-payment-processor-v2https://itokenly.com/hacks/limit-break-payment-processor-v2Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.