Live Prices
NFTs

White Hat Rescue Saves 23,155 NFTs Worth $6M Following LimitBreak Smart Contract Bug

TheCryptoDesk Editorial · 2m read
White Hat Rescue Saves 23,155 NFTs Worth $6M Following LimitBreak Smart Contract Bug

On September 25, pseudonymous security researcher Quit, who serves as VP of Blockchain at Yuga Labs, executed an emergency white hat rescue operation that transferred 23,155 NFTs worth approximately $6 million to safe custody following an exploit in LimitBreak's Payment Processor V2 contract.

Discovery and Emergency White Hat Extraction

The security incident first surfaced when NFT trader Cirrus reported that an unfamiliar wallet, 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33, was pulling 3,832 NFTs out of more than 100 compromised wallets. Quit later confirmed the activity was part of a white hat intervention to prevent malicious actors from draining exposed assets, noting that the tokens would be returned once risks were mitigated.

Earlier that morning at 9 a.m. EST, an attacker utilized the smart contract bug to steal 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Despertae Apewives. Because Payment Processor V2 could not be paused, running a white hat counter-operation was the only option available to secure exposed collections. LimitBreak was able to pause Payment Processor V3 upon notification, though V3 on ApeChain was also temporarily unpausable.

Vulnerability Scope and Unrecovered WETH

Despite relocating over 23,000 digital collectibles, the emergency response could not prevent all losses. Quit revealed that the vulnerability allowed a secondary reverse exploit vector targeting WETH, leaving 660 WETH (valued at $1.7 million) unrecovered before the white hat script could intervene. Affected NFT holders will be able to claim their assets after revoking existing contract approvals.

Key details of the incident include:

  • 23,155 NFTs worth nearly $6 million rescued and moved to wallet 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33.
  • Initial exploit at 9 a.m. EST took 10 Meebits, 50 Otherdeeds, 10 World of Women, and 235 Despertae Apewives.
  • 660 WETH worth $1.7 million lost due to a reverse attack vector.
  • Emergency action triggered after Magic Eden NFT approvals exposed wallets to vulnerability risks.

The rescue operation occurred on the same day as a separate major incident, where a Bitget security breach resulted in over $351 million drained from exchange hot and warm wallets.

Why It Matters

This event highlights the inherent security trade-offs of unpausable smart contract designs in Web3 protocols. While immutable contracts ensure code execution without centralized interference, they leave protocols vulnerable to active exploits when bugs emerge, forcing security researchers into race-against-the-clock white hat operations. Going forward, project creators must carefully evaluate emergency fallback options, while NFT traders should regularly audit and revoke outdated marketplace approvals to reduce personal wallet exposure.

Read next