PaymentProcessorV2 Exploit: 0xQuit’s Rescue and What Collectors Should Do
On Monday, September 28, 2026, Quit (@0xQuit)—Yuga Labs VP Blockchain and founder of oSnipe—posted a technical thread explaining the PaymentProcessorV2 exploit and the whitehat rescue that followed.
His short version is the one collectors need to remember: Payment Processor trusted an ERC-2771-style “original sender” supplied through a trusted forwarder. That sender could be forged.
Full thread: https://x.com/0xQuit/status/2104680884360339829
What happened (Quit’s Sep 25 timeline)
In a detailed note posted Friday, September 25, 2026 (about 4:06 AM CDT / 9:06 AM EST), Quit wrote that an attacker had abused a bug in Payment Processor V2 earlier that morning. The first wave he called out included 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs, and 235 Desperate Apewives.
He said it took more than 12 hours for someone to flag the activity to him. After digging in, he concluded many more NFTs were exposed to the same path.
Quit contacted Limit Break. Per his account, the team quickly paused Payment Processor V3, which carried the same issue. V2 was not pausable, so the path to protect exposed inventory was a whitehat operation. He also noted that V3 on ApeChain was temporarily in a state where it could not be paused, so approved ApeChain assets needed rescue as well.
His headline numbers from that post:
- 23,155 NFTs rescued, “worth north of $5.7M USD”
- A related path could be used in reverse against WETH; 660 WETH was at risk and was not recovered in time
He credited @Boomskite for flagging the initial exploit transaction, and @coffeedev, @0xjustadev, and @whiteoakkong for assisting the recovery.
Primary source: https://x.com/0xQuit/status/2103410682368512505
Why “revoke listings” wasn’t enough
Quit’s Sep 28 thread frames the bug around trusted-forwarder / ERC-2771-style original-sender trust. In plain collector language: if a marketplace settlement contract treats a forwarded “original sender” as gospel, and that value can be forged, standing operator approvals become the attack surface—not a live listing signature you can simply cancel.
That is why culture keeps circling the same hard lesson: approvals outlive the marketplace tab you closed. Magic Eden has said publicly that it adopted Limit Break’s Payment Processor V2 to settle EVM trades in 2024, stopped using it in October 2024, and shut its EVM marketplace in Q1 2026—while still urging anyone who listed or traded on that EVM stack to revoke the old Payment Processor permissions. Disconnecting a wallet from a website does not revoke onchain approvals.
Revoke first, then claim (as Quit published)
Quit’s follow-up listed contracts to revoke via revoke.cash or a similar tool:
- Payment Processor V2 (Ethereum) — also cited for Polygon/Base in his guidance:
0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 - Payment Processor V3 (ApeChain):
0x9a1D00000000fC540e2000560054812452eB5366
Source: https://x.com/0xQuit/status/2103410684616708576
Rescued NFTs were moved to safety so they would not sit under the same exploitable approval. Quit’s reclaim flow requires owners to revoke the PaymentProcessor approval first, then claim.
Official claim site (verify the URL carefully): https://nftsaresafu.xyz/
As of the site’s own update on Sep 28, 2026, it stated PaymentProcessor V2 was exploited on 9/25/2026, listed rescued inventory for reclaim, and showed reclaim progress counters on-page. Treat those site counters as claim-portal status, and treat Quit’s Sep 25 figures (23,155 NFTs / ~$5.7M / 660 WETH not recovered) as his contemporaneous rescue statement.
Scam warning: Fake “recovery” DMs and lookalike domains follow every high-profile incident. Reach the claim tool only through Quit’s verified posts or the exact URL above. Revoking does not return assets that already moved to attackers; it reduces ongoing exposure and is required before Quit’s reclaim path.
What this means for creators and collectors
- Approvals are culture infrastructure. If you ever traded on an EVM marketplace that routed through Payment Processor, assume the approval may still be live until you check.
- Trusted forwarders are not a vibe—they’re a trust boundary. Quit’s short version is a design lesson: if “original sender” can be forged, operator approvals become remote control.
- Pausability matters. Quit’s timeline shows V3 could be paused; V2 could not. Creators evaluating marketplace rails should ask who can halt settlement contracts—and what happens when they cannot.
- Whitehats bought time; collectors still have homework. Rescued jpegs only stay safe if owners revoke before reclaiming.
This is not a how-to exploit. It is a collector-hygiene story: old marketplace rails, sticky approvals, and why culture still depends on people like Quit who treat other people’s bags as worth a sleepless night.
Related on NFT Culture
- Rumored phishing attack on OpenSea… revoke permissions
- Foundation winds down: what it means for the NFT ecosystem
- Bidding farewell to Nifty Gateway
Sources
- Quit technical thread (Sep 28, 2026): https://x.com/0xQuit/status/2104680884360339829
- Quit rescue note (Sep 25, 2026): https://x.com/0xQuit/status/2103410682368512505
- Quit revoke addresses: https://x.com/0xQuit/status/2103410684616708576
- Claim portal: https://nftsaresafu.xyz/
- Revoke.cash incident page: https://revoke.cash/exploits/magic-eden?chainId=1