Limit Break exploit: where the 542 WETH went, and the attacker still draining wallets

PublicAML · On-chain investigation · 29 September 2026

On 24–25 September 2026 an old NFT trading contract, Limit Break’s Payment Processor V2, was used to take NFTs and WETH from wallets that had approved it years ago, most of them while listing on Magic Eden in 2024. Whitehats led by 0xQuit rescued about 23,000 NFTs. The money was a different story: we counted 542 WETH pulled out of wallets through the same contract, most of it in half an hour on the morning of 25 September. Half went to an MEV bot that has agreed to return 90%. Of the rest, 165 ETH sits untouched in one attacker wallet, 46 ETH went into Railgun, and the same attacker was still draining WETH on 29 September. On the NFT side, one wallet collected about 30,800 NFTs, including 1,075 ENS names, after the rescue had ended, and still holds most of them.

542 WETH

taken from wallets through Payment Processor V2, 25–29 Sep

282.7 WETH

captured by an MEV bot that agreed to return 90%

223 ETH

parked on one attacker wallet, never moved

46 ETH

sent into Railgun by a second attacker

How the exploit works

Payment Processor V2 (0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834) settles NFT trades. A wallet that lists an NFT gives it permission to move the whole collection, and that permission never expires. Magic Eden settled its Ethereum trades through it from about February to October 2024 and left long ago; the approvals stayed. V2 cannot be paused.

The bug let anyone settle a "sale" on an approving wallet’s behalf without its signature. For NFTs, the attacker bought them at a price of zero. For WETH, the trick ran the other way: the attacker minted a throwaway NFT and "sold" it to the victim for the victim’s entire WETH balance, and the contract collected the payment. Limit Break has not published a post-mortem; the pattern above is what the events on chain show.

The first abuse on record is 24 September 13:07 UTC: 305 NFTs from one wallet — 10 Meebits, 50 Otherdeeds, 10 World of Women and 235 Desperate Apewives — to 0x0e9E147AF2108e5354EfB28740Cade8e7422d1c7, exactly as 0xQuit described it. It was noticed twelve hours later, and 0xQuit’s whitehat operation then rescued about 23,000 NFTs overnight. Between 23 and 29 September we count more than 108,000 zero-price NFT transfers out of 13,182 wallets, rescues and thefts together.

The money: 542 WETH in half an hour

Around 08:00 UTC on 25 September the WETH path was found. Between 08:26 and 08:57 almost every wallet that still had WETH and an old approval was emptied; after that only crumbs were left. In total we count 542.1 WETH, about $1.4 million at the 25 September price, across 6,650 drain transactions.

The first and largest transaction, 281.66 WETH from 25 wallets at 08:26, came from an MEV bot operator, 0x23245F620d1e910ad76e6B6De4f8284A53C9Ad2d: it reached the WETH before anyone else. Its payout chain split the money 90/10 as it has done since late 2025, and 253.49 ETH landed on 0xbfA8d986363e225Ea10d43a8838280bC2466A68e. On 29 September 0xQuit said this operator has agreed to return 90% to affected users through nftsaresafu.xyz. We do not call it the attacker and have not labelled it.

The rest went to attackers who each deployed a fresh contract per batch of victims. 0xcccc640018f8c2b00fa45F456017AD2378Eb3447 took 166.5 WETH in 13 transactions, 0xDeaD668FDC60b33Fd2D10dD40070b75177bEeCd2 took 44.8 WETH in 16, and 0xfc3fAcD67138966aB0c841E905B0C4BCA1AbE92F — the address @sprunky_eth found hard-coded as the controller in the drain contracts — took 10.6 WETH. Six more addresses took between 1 and 7 WETH each.

When (UTC, 2026)FromToAmountTx
24 Sep 13:070x9A1D00…ac68340x0e9E14…22d1c7305 NFTs
first abuse on record
0x9050e2…4193d3
25 Sep 08:260x9A1D00…ac68340x860Bb7…739C8d281.66 WETH
MEV bot, returning 90%
0xdd3ab3…e7a96b
25 Sep 08:260xB770f7…7898E20xbfA8d9…66A68e253.49 ETH
MEV operator’s 90% share
0xf53b2c…c54dd1
25 Sep 08:30–08:530x9A1D00…ac68340xcccc64…Eb3447166.5 WETH (13 txs)
WETH drained via PPv2
0x3b70dd…c03360
25 Sep 08:48–08:560x9A1D00…ac68340xDeaD66…bEeCd244.8 WETH (16 txs)
WETH drained via PPv2
0x39e099…d924fd
25 Sep 08:42 / 09:170xC02aaA…756Cc20xcccc64…Eb344797 + 70.54 ETH
WETH unwrapped to ETH
0x763a8d…e0c9a4
25 Sep 10:530xDeaD66…bEeCd20x4025ee…F6bE8a46 ETH
into the Railgun pool
0x630f5c…a0cc96
25 Sep 14:270xcccc64…Eb34470xddddD0…d52c24165 ETH
parked, never moved
0xa80166…f24759
26 Sep 06:25 – 27 Sep 08:230x91d7F7…6eb6530x22657B…52B4F4~30,800 NFTs (3,252 txs)
NFTs taken after the rescue
0x8e8983…d9a6b9
28 Sep 13:110x71cF3f…E7fe330x22657B…52B4F4on-chain message
0xQuit asks for return
0xed0335…5ef217
26 Sep 20:220x40986a…CBA5a80x4e79b1…dB74447 ETH
NFT sale proceeds
0x1615b7…84f4a6
27 Sep 01:050x4e79b1…dB74440xEC6181…fe9A9E6.33 ETH
NFT sale proceeds
0x3712a8…e0dec1
27 Sep 01:09–01:160xEC6181…fe9A9E0xd90e2f…24F31b6.3 ETH (9 deposits)
into Tornado Cash
0x0a21b4…a99541
29 Sep 14:300x9A1D00…ac68340x3d32E8…164Da00.15 WETH
still draining on 29 Sep
0x389c92…07c5fb

Where the attackers’ share is now

0xcccc640018f8c2b00fa45F456017AD2378Eb3447 unwrapped its WETH (97 ETH at 08:42 and 70.54 ETH at 09:17) and at 14:27 sent 165 ETH to 0xddddD01e33c4dcF91bb0BDdDa40788dFAcd52c24. That wallet now holds 223 ETH — it had already received 46 ETH from the same attacker on 29 August — and has never sent a transaction. It is on our watch list.

0xDeaD668FDC60b33Fd2D10dD40070b75177bEeCd2 unwrapped its share and at 10:53 on 25 September sent 46 ETH through Railgun’s relay contract (0x4025ee6512DBbda97049Bcf5AA5D38C54aF6bE8a) into the Railgun privacy pool. On 28 September it made two 0.1 ETH test deposits into Tornado Cash.

Both wallets are being sent fake tokens named "ETH" from look-alike addresses that copy their first and last characters. That is address poisoning aimed at whoever copies them next; none of it is counted here.

Update: the NFT side — one wallet still holds most of 30,800 NFTs

The whitehat rescue ended on the morning of 25 September. The largest haul came after it. On 26 and 27 September two fresh wallets, 0x91d7F7C9d08a50Bb252F1EF2E0a5749A396eb653 and 0x40986ac3089d3963095c07506F02746F2ACBA5a8, sent 3,252 transactions through the same contract and delivered about 30,800 NFTs from 2,697 wallets and 552 collections to one address, 0x22657B3eb4B984f0137C58e0713ae125d752B4F4. Among them: 4,588 Backstreet Dog, 3,301 Beanz3D, 2,432 CNP Jobs, and 1,075 ENS names plus 434 wrapped ENS names — domains that can be used to impersonate their former owners.

The wallet was created for this: its first transaction is on 26 September at 06:58 UTC, gas from 0x9E4A8Ca74A8b07915E3f89107CAE77Ff413AD255. It has moved out only about 400 of the NFTs, so the rest are still there. On 28 September 0xQuit’s recovery wallet (0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33, the contract owners now use to reclaim rescued NFTs) sent it an on-chain message asking to return them. There has been no reply on chain.

The cluster did cash out some. 0x9E4A8Ca74A8b07915E3f89107CAE77Ff413AD255 sold NFTs into bids on Seaport and Blur for about 8 ETH and passed it to 0x40986ac3089d3963095c07506F02746F2ACBA5a8, which sent 7 ETH to 0x4e79b1A43df1B9E7C32359170f49fB6Db0dB7444. From there 6.33 ETH went to 0xEC6181818C17D1E6B1e243831EE0235e39fe9A9E and, within ten minutes on 27 September, 6.3 ETH into Tornado Cash in six 1 ETH and three 0.1 ETH deposits.

If one of your NFTs or ENS names left your wallet on 26 or 27 September at a price of zero, it is most likely on this address.

It has not stopped

V2 still cannot be paused, and 0xcccc640018f8c2b00fa45F456017AD2378Eb3447 is still using it. On 29 September at 14:30 UTC its contract 0x3d32E8Feb1551E9771F1E485a2B1237a80164Da0 minted a new token and "sold" it to a wallet for that wallet’s 0.15 WETH. Any wallet that still approves Payment Processor V2 for WETH loses whatever WETH arrives in it.

If you ever listed on Magic Eden’s Ethereum marketplace or anywhere else that used Limit Break’s Payment Processor, revoke approvals to 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 on revoke.cash — for your NFT collections and for WETH. Revoking does not return what already moved; the MEV operator’s refund is claimed at nftsaresafu.xyz.

What this page does not say

It names nobody. 0xcccc640018f8c2b00fa45F456017AD2378Eb3447 has been active since April 2026 — it put 140 ETH into Tornado Cash in April and May and has deployed dozens of contracts since June — but it did not use Payment Processor V2 before 24 September; we checked its transactions one by one. What those earlier contracts did is outside this page.

Apart from the wallet above, the zero-price NFT transfers are not split into rescues and thefts: the recipients include 0xQuit’s whitehat contracts and several unrelated parties, and we do not label a wallet as an attacker on the strength of receiving NFTs alone. The wallets that first paid gas to the NFT executors lead into an older, wider group of addresses that we have not traced.

The attacker addresses on this page are labelled in the PublicAML risk graph, so any service screening against it will see them. The MEV operator’s wallets are not.

Sources: every Payment Processor V2 event on Ethereum from block 26,030,000 to 26,083,400 (Routescan), decoded with the verified contract ABI; transactions and balances from Blockscout, read on 29 September 2026; timeline and rescue figures from 0xQuit’s thread; drain-contract analysis by @sprunky_eth; Magic Eden’s statement. Dollar values at the 25 September ETH price. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.