TREE NEWS update: An attacker exploited a Payment Processor V2 vulnerability at 9am ET, stealing 10 Meebits, 50 Otherdeeds, 10 WoW and 235 Desperate Apewives. After LimitBreak paused the also-affected V3, a whitehat operation moved 23,155 NFTs worth over $5.7 million to safety. The flaw could also be reversed to steal roughly 660 WETH, which was not recovered.
Payment Processor V2 Exploit Drains NFTs; Whitehats Rescue $5.7M+
The notable detail is not the theft itself but the reversal vector: the same flaw that enabled the NFT drain could also pull roughly 660 WETH, which went unrecovered, suggesting the exposure was broader than a single collection sweep. That whitehats moved over 23,000 NFTs to safety shows the response was coordinated and fast, though it depended on pausing V3 rather than fixing the underlying contract. The open question is whether the unrecovered WETH points to a limitation of whitehat rescues or simply a window that closed first.
Generated by AI for reference only.
Share on WeChat
Open WeChat → Scan → then tap "…" to send to a chat or Moments.
Tap "…" in the top-right corner to send to a chat or share to Moments.