Limit Break Payment Processor exploit — $1.8M lost on Ethereum, ApeChain, Polygon, Base
Limit Break Payment Processor lost an estimated $1.8M on Ethereum, ApeChain, Polygon, Base (token approval abuse), according to the DeFiLlama hacks database. Users and integrators should review exposure and follow the project's official channels.
Vuln-watch · relayed from the DeFiLlama hacks database; see Source & attribution below
Summary
Limit Break Payment Processor lost an estimated $1.8M on Ethereum, ApeChain, Polygon, Base (token approval abuse), according to the DeFiLlama hacks database. Users and integrators should review exposure and follow the project's official channels.
Incident
- Protocol: Limit Break Payment Processor
- Date (UTC): 2026-09-24
- Estimated loss: $1.8M
- Chain(s): Ethereum, ApeChain, Polygon, Base
- Technique: Token Approval Abuse
- Classification: Access Control
- Target: NFTfi
Recommended actions
- Revoke token approvals granted to Limit Break Payment Processor contracts until the project confirms they are safe
- Integrators: pause or delist affected assets and monitor for attacker fund movements
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
This 0xCERT advisory relays an incident recorded in the DeFiLlama hacks database (https://defillama.com/hacks). Figures are preliminary estimates and may be revised; refer to the project's own post-mortem for the authoritative record. Report additional details to 0xCERT at https://www.0xcert.com/report.
References
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-24 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0146/signed.txt | gpg --verify