PublicAML

Limit Break Suffers $1.7 Million NFT Drain via Payment Processor Exploit

Limit Break experienced a significant security incident involving its Payment Processor V2 on Ethereum. An attacker impersonated NFT holders to drain approximately $1.7 million in user-approved NFTs.

An attacker exploited Limit Break’s Payment Processor V2 by impersonating holders who had approved the contract as an NFT operator. This allowed the attacker to purchase NFTs at a zero price, leading to the unauthorized transfer of assets. The incident resulted in the draining of about $1.7 million in user-approved NFTs across several transactions while the attack was still ongoing.

During the incident, a whitehat intervened and managed to rescue a portion of the assets. The whitehat indicated that the recovered assets would be returned once they were no longer at risk. The attack highlights vulnerabilities in the approval mechanisms of NFT transactions, particularly when contracts are involved.

The incident took place on the Ethereum blockchain, which is known for its smart contract capabilities. This context is relevant for tracing the flow of assets and understanding the impact of the exploit on the affected users. However, specific addresses involved in the transactions were not disclosed in the report.

Sources

Share:XTelegramLinkedIn
Limit Break Suffers $1.7 Million NFT Drain via Payment Processor Exploit | PublicAML