🗺️ Figuring out what to do next. 📴 Used to be terminally online in Web3. 📬 DMs open for interesting things. Prev: @RevokeCash · @BoringSecurity
🇩🇪
Joined October 2021
- Tweets30.5K
- Following1.1K
- Followers8.7K
- Likes54.8K
Make sure this will not be an issue by revoking your approvals regularly. How?
nitter.cf/wiimee/status/21039337…
WiiMee retweeted
I feel for everyone who has been hit by the Magic Eden fiasco.
Getting hacked sucks, I know… you never feel the same about this space after it.
I am grateful to know someone like @wiimee who gave so much time to making this space secure. I wish more had listened to him…
THIS SHOULD BE THE MOST VIRAL POST ON @x because this is 100% the reality of all of CT. Every single letter in this post is the absolute truth. And thats the worst part.
WiiMee retweeted
I had forgotten about this, but now that it came up, I remember doing what @wiimee told us to do.
This exact post was the start of my friendship with him
This is the reason why I was safe from this exploit.
Otherwise I would have still been connected there
Time and time again, this man keeps earning more respect and rightly so!
Thank you Wii!
I didnt know it, but you could foresee it, and cz of your insight and trust, I am safer today.
Do yourself a favor and follow up on this man for better security
I wouldn't change a single word
This did NOT age well….
@wiimee deserves a million followers for being one of the web3 heroes.
Let this exchange between @Rahim_mahtab and @wiimee from February 2026 be an education and warning for everyone…
Thank you, Tony. 💜
For years I put a lot of effort into making wallet security easier to understand. Seeing that work recognized honestly warms my heart.
I ultimately stepped away because I wasn't reaching enough people and it wasn't financially sustainable.
Appreciate you!
This did NOT age well….
@wiimee deserves a million followers for being one of the web3 heroes.
Let this exchange between @Rahim_mahtab and @wiimee from February 2026 be an education and warning for everyone…
WiiMee retweeted
When I first started Boring Security I had one of our contributors make a spreadsheet of "accounts with approvals to services with their apes in it". Dangerously high, so we tried to take action...
For a while we tried going around DMing everyone about their dangerous approvals, but that went as well as you might imagine. So we gave up and tried to create an Alumni program and reward folks with a few ApeCoin and steeply discounted/free branded Ledgers for taking our classes in partnership with the ApeCoin DAO, and ThankApe (at the time). Better than nothing...
The whole NFT space is extremely vulnerable to the broader negligence to end-user education and ETH UX for safety. I know it's much easier to blame each protocol whenever this happens, but the reality of it is, good security hygiene prevents this. Not selling your assets? Put them in a wallet address that has no approvals on it.
I know this sounds simple, but the reality is the average person needs several hours of safety education to have a chance in hell in not losing their assets here, even in 2026 it's only gotten more difficult with Smart Accounts, Delegation and the like. That makes the busy, non-technical artists and creatives the most vulnerable. The people who made the space worth waking up for have mostly all been hacked, few stayed.
The NFT community is one that is experiencing a weird kind of gentrification and shrinking, where all the cool people get displaced, not because they can't afford to hang, but because the people who made this place cool all got scammed, rugged, or exploited because of otherwise well-intentioned, albeit negligent, actors.
To date, few projects have done anything proactive for its community wrt security, aside from the ApeCoin DAO funding the existence of Boring Security, and Pudgy Penguins offering a Safety Pin SBT (which even got a$PENGU alloc!), and of course the projects partnering with Boring Security for education classes.
But ultimately Quit, BSec, other security researchers, and Yuga continuously bailing out the poor security practices of users and negligent protocols is unsustainable. Yuga is shelling out fistfuls of ETH and man hours to cover for NFTTrader, Flooring, and now ME's mistakes.
We need a lot, but at the very least, how about NFT drops that award based on no approvals and good security hygiene? This is a problem in the broader crypto ecosystem as well, but there is no real "community" in DeFi, perps, or memes, so likely, no change will happen there.
There are a million other things I think we "need" and are working on some, but this whole space needs to come together to see that we need to incentivize secure behavior of end-users, because the UX/Security improvements that were "supposed to save us" 5 years ago still haven't arrived.
I really wish I'd been able to get this message to more people.
Nobody should have to learn that approvals outlive a platform by losing their assets.
Another one bites the dust.
Reminder: approvals don't expire.
So when an dApp shuts down, your permissions will outlive it.
If you used Magic Eden and they shut down, do a review + revoke via @RevokeCash.
According to Quit there's a whitehat operation going on rescuing the NFTs that are at risk by the Limit Break contract.
In case you don't wanna risk it:
- Use @RevokeCash
- Search for spender: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834
- Revoke that shii
Replying to @CirrusNFT
hey ya this is a whitehat and everything in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 is safe and will be returned once they are no longer at risk
Well, looks like there's still something going on. nitter.cf/wiimee/status/21034648…
🚨 The NFT drain attack seems to be ONGOING!
Lazy Lions and Kodamara's have been stolen in bulk 15 minutes ago.
Revoke any approvals to the Limit Break v2 contract on Ethereum!
0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834
According to Quit there's a whitehat operation going on rescuing the NFTs that are at risk by the Limit Break contract.
In case you don't wanna risk it:
- Use @RevokeCash
- Search for spender: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834
- Revoke that shii
See @0xQuit 's latest update here.
Brutal day for collectors in this space. I know this feels like a personal loss for you Quit, but you did a lot to protect many already. Wish we could've educated people better, too. It's sad.
nitter.cf/0xQuit/status/21034759…
The bulk of the damage is done, but there are still assets that are vulnerable to the exploit. I'm doing what I can to sweep what's left but hundreds of scammers are also doing the same.
Whether you're affected or not, if you have open approvals to the addresses below, please revoke them. The open approvals can and will be used against you if affected assets are returned to your wallet while they're still open.
Replying to @wiimee @RevokeCash
Yessir. Update here:
nitter.cf/0xQuit/status/21034106…
At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives.
It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the same exploit.
I got in touch with the team over at LimitBreak and they quickly paused Payment Processor V3, which was subject to the same exploit. Unfortunately, V2 was not pausable, so the only path towards protecting affected assets was to run a whitehat operation.
Similarly, V3 on ApeChain is temporarily in a state where it cannot be paused, so ApeChain assets approved to V3 needed to be saved as well.
All in all, we rescued 23,155 NFTs worth north of $5.7M USD.
We later discovered that a similar exploit could be used in reverse to steal WETH. 660 WETH was at risk, which we unfortunately were not fast enough to recover. Apologies to those affected.
Shout out to @Boomskite for flagging the initial exploit tx to me, and @coffeedev @0xjustadev and @whiteoakkong for acting quickly and assisting with the recovery.
All NFTs are safely relocated. Soon, owners will be able claim them back after revoking the exploitable approvals.
Addresses to revoke below.