LimitBreak (DigiDaigaku NFTs) exploit discovered on Ethereum.
Security & Exploits ·
An exploit targeting LimitBreak's Payment Processor V2 contract on Ethereum has drained approximately 1.7 million dollars in user-approved NFTs across roughly three transactions, with the attack reportedly ongoing. The attacker has exploited the contract by impersonating NFT holders and purchasing their assets at zero price, leveraging operator approvals that users had previously granted to the Payment Processor V2 contract.
The vulnerability centers on how the Payment Processor V2 was authorized as an NFT operator. Any user who approved this contract as an operator permission is exposed, regardless of whether they have active listings or have attempted to cancel them through other means. The attacker's addresses include 0x71cF3f5724bD2B72Ef6464992aCd26216De7fe33, 0x415F981b474b2E060D314BEc14461d9aeEf70B1a, and 0xB48D6Af77c5E3B99876eA71B38E9c814bA5B1C8E, with the spender contract identified as 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834.
Affected users are advised to immediately revoke operator permissions granted to Payment Processor V2, as standard mitigation steps like canceling listings or resetting master nonces do not remove the operator grant that enables the theft. The scope of total losses and whether additional transactions may occur remain unclear.