TREE NEWS update: Attackers exploited Limit Break’s Payment Processor V2 contract to impersonate NFT holders and transfer previously approved NFTs at zero price, with roughly three transactions draining about $1.7 million worth of NFTs so far. Users who granted the contract approval to operate their NFTs should revoke it immediately.
Limit Break Hit by Ongoing Attack; ~$1.7M in NFTs Stolen
The exploit targets an approval mechanism rather than a token or chain, which is the more consequential detail: the stolen assets moved only because holders had already granted the contract standing permission to operate their NFTs. That puts the burden on users to revoke approvals, and it shows how a single compromised processor contract can become a shared point of failure across a collection's entire holder base. Whether the drain is contained to these three transactions, or whether the same approval exposure extends further, is the open question.
Generated by AI for reference only.
Share on WeChat
Open WeChat → Scan → then tap "…" to send to a chat or Moments.
Tap "…" in the top-right corner to send to a chat or share to Moments.