OG Satirical Trash Artist. Not-So-Supermarket Owner. Strong Personality. Politically Incorrect. Not A One Trick Pony. Shotgun Under The Register. Try It.

Southern California
***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!*** The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY The public story around @0xQuit is usually reduced to one word: “whitehat.” That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role. The documented record shows that Quit is simultaneously: VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations. That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol. Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts. THE MEV BUSINESS Quit founded oSnipe. Its public description is direct: “Your personal MEV sniper. By @0xQuit.” One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9 A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report: oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth. MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately. That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement. Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it. The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles. THE WALLET IDENTITY LAYER Quit’s publicly attributable wallet history is broader than a single address. High-confidence Quit-linked addresses include: quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60 unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7 quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620 The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction. WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT By September 2026, Quit was positioned at the intersection of: MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response. The next posts show how that network formed before the exploit ever occurred. Sources nitter.net/oSnipeNFT twstalker.com/0xQuit/status/… etherscan.io/address/0x5c049… etherscan.io/address/0x862c9…
31
6
56
26,102
***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!*** The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY The public story around @0xQuit is usually reduced to one word: “whitehat.” That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role. The documented record shows that Quit is simultaneously: VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations. That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol. Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts. THE MEV BUSINESS Quit founded oSnipe. Its public description is direct: “Your personal MEV sniper. By @0xQuit.” One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9 A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report: oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth. MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately. That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement. Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it. The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles. THE WALLET IDENTITY LAYER Quit’s publicly attributable wallet history is broader than a single address. High-confidence Quit-linked addresses include: quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60 unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7 quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620 The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction. WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT By September 2026, Quit was positioned at the intersection of: MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response. The next posts show how that network formed before the exploit ever occurred. Sources nitter.net/oSnipeNFT twstalker.com/0xQuit/status/… etherscan.io/address/0x5c049… etherscan.io/address/0x862c9…
31
6
56
26,102
Anonymous Nobody retweeted
FEW.
Masterpiece look into the recent NFT Magic Eden Exploit and the shady “relationships and network of the “whitehat rescue”. Much like I’ve found, with TheDAO exploit, several people on Seal911, and most major exploits in Crypto since inception, the Whitehats are at best Greyhats, but often Blackhats masked as Whitehats.
4
190

ALT the dark knight joker GIF

1
2
153
Oh, you need an ELI5. Ok. The “random independent whitehat saves the day” version leaves out a large amount of relevant context. Quit was already embedded in the engineering, marketplace, MEV, security and financial-product ecosystem surrounding the protocols involved. His response to the exploit occurred through people and infrastructure with which he had pre-existing relationships. The easiest way to understand 0xQuit is this: He is not just “the guy who showed up after a hack.” He has spent years placing himself at the intersection of security, marketplaces, MEV, NFT trading infrastructure, Yuga, Limit Break-adjacent engineers, and financialized NFT protocols. That positioning is real and documentable. What is not established is that the entire network acted together criminally. Think of it like this. A normal independent security researcher is more like a locksmith: they inspect locks, tell you where the weaknesses are, and maybe help when somebody breaks in. Quit is closer to a locksmith who also: builds high-speed tools for getting through doors before other people; works for one of the biggest property owners in town; helps operate a financial business inside some of those buildings; invests alongside other security and engineering people; has previously written code with engineers who built the lock system; uses the lock company’s permission system in another business; and then becomes one of the main people responding when that lock system fails. That does not automatically mean he arranged the burglary. But it means he is inside a lot of the systems involved, not standing outside them. Start with oSnipe Quit founded @oSnipeNFT. oSnipe is an NFT MEV/sniping system. In simple terms, it is built to recognize profitable NFT transactions and compete to execute them faster or more effectively than ordinary users. Ordinary users like you. That means Quit has direct experience with: transaction ordering; private execution; paying builders/validators for priority; taking advantage of time-sensitive pricing differences; exploiting market inefficiencies. That is important because MEV is fundamentally about who gets to act first and who captures the value created by someone else’s transaction. So Quit is not merely a security person who understands how attackers work. He runs technology designed to exploit timing and execution advantages in markets. His operational oSnipe wallet is: 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet later funded the September 2026 Limit Break rescue wallet. So the same operational ecosystem used for his commercial MEV project was directly involved in the incident response. Quit already knew Limit Break engineers before this incident. This is one of the most important facts. In February 2024, Quit helped author DN404. Other contributors included: @0xjustadev @0xCygaar @optimizoor @PopPunkOnChain @AmadiMichaels @0xjustadev They are all associated with Limit Break engineering. So Quit and a Limit Break engineer were already writing smart-contract code together more than two years before the September 2026 exploit. That matters because when the hack later occurred and Quit says he contacted Limit Break, he was not reaching out to some company he had never dealt with before. He was contacting people inside an existing technical network. At almost the same time, Limit Break entered the Magic Eden/Yuga marketplace stack. In 2024, Limit Break’s Payment Processor technology was adopted for the Magic Eden/Yuga Ethereum marketplace. That is the same general contract family that became central to the 2026 exploit. Magic Eden later confirmed that old approvals to Payment Processor V2 remained active after it stopped using the processor in October 2024. Those old approvals are what left users exposed. So by early 2024: Quit was working with a Limit Break engineer. Limit Break was entering the Yuga/Magic Eden marketplace infrastructure. Quit had not yet officially joined Yuga. That timing is worth understanding. Then comes James Hall. James Hall was already a major engineering figure at Yuga. In July 2024, both Quit and James Hall appeared as investors in the same Ethos funding round. Then, a few months later, Quit joined Yuga as VP of Blockchain. So before Quit officially worked at Yuga, he and Yuga’s engineering leadership were already participating in the same investment network. Again, that does not mean wrongdoing. But it means there was already a professional/financial connection. Then Quit joins Yuga. After joining Yuga, Quit becomes responsible for blockchain strategy and ApeChain. James Hall continues leading engineering and later takes responsibility for Otherside. Then in February 2026 Hall publishes a technical guide for the Otherside marketplace. That guide explicitly says: the Otherside MarketplaceOrderRegistry is built on top of Limit Break Payment Processor V3. The V3 address is: 0x9a1D00000000fC540e2000560054812452eB5366 That is not some minor dependency. It is the settlement engine behind the marketplace. So now the relationship becomes: Quit → Yuga blockchain leadership James Hall → Yuga engineering / Otherside Otherside → Limit Break Payment Processor V3 That is the same Payment Processor family that later becomes part of the September incident. Guardian enters the picture too. Guardian audited Yuga’s NFT Shadows system. Guardian’s own case study prominently displays a testimonial from 0xQuit of Yuga Labs. Guardian also appears in the broader investor/security network around g8keep with Quit and other Solidity people. And later Guardian infrastructure was used for Limit Break AMM security work. The important thing is not that Guardian “caused” anything. It is that the same relatively small group of security engineers, auditors, investors and protocol builders repeatedly shows up around: Yuga; Limit Break; DN404; g8keep; Gaslite; marketplace infrastructure. FWAP is where it gets more operational. Quit is also involved with FWAP/FWAPHouse. This is important because FWAP is not merely a social association. There are wallet-level operational connections. The FWAPHouse deployer is: 0x3561b02bB427FB5aBA9AF0EA005b12A49246DF21 That wallet funded: 0xd7395e1d103837607a4ca9aa9389cbf688a06132 Then Quit’s oSnipe operating wallet: 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E used Limit Break’s Creator Token Transfer Validator V5: 0x721C008fdff27BF06E7E123956E2Fe03B63342e3 to add: 0xd7395e1d103837607a4ca9aa9389cbf688a06132 to validator list 13. That is a direct operational loop: FWAPHouse funds an address → oSnipe adds that address into Limit Break transfer-control infrastructure. That is much more significant than two people knowing each other. Limit Break’s Transfer Validator is essentially a programmable permission system for NFT transfers. It supports allowlists, authorizer lists, security levels and other transfer rules. So in plain English: A wallet from Quit’s MEV operation was configuring permissions inside a Limit Break transfer-control system for a wallet funded by Quit-associated FWAP infrastructure. That is exactly the kind of relationship people should understand. Then comes FWA and Rhynotic. FWAP later integrates Fake World Assets, or FWA. FWA is operated by @token_works, with @Rhynotic publicly involved. FWA is effectively a financialized NFT market mechanism where NFTs are paired with ETH backing and transactions occur through structured on-chain rules. Quit publicly discusses and explains FWA mechanics and FWAP’s integration with it. That creates another important combination: Rhynotic / TokenWorks → FWA financial mechanics FWAP → integrates FWA Quit → operates/explains FWAP Quit → also operates oSnipe MEV That matters because MEV becomes more valuable when transactions are predictable and involve pricing, pool state, backing levels, settlement or arbitrage. In very simple terms: If you know how a machine is going to move prices, and you also own a high-speed trading engine that can act before or after users, that creates a conflict that should be independently audited. That does not establish that he exploited FWA or FWAP users. But the technical ability and operational overlap are real. Now look at the September 2026 incident. The vulnerable contract was Limit Break Payment Processor V2: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 An attacker exploited it and stole 305 NFTs. Magic Eden says old user approvals remained active even though it stopped using V2 in 2024. Quit says more than 12 hours later @Boomskite alerted him. Quit investigated. Quit contacted Limit Break. Limit Break paused V3 where possible. V2 could not be paused. Quit says a defensive operation then moved 23,155 NFTs worth more than $5.7 million into custody. Who helped? Quit publicly credited: @0xjustadev @whiteoakkong @coffeedev Remember: @0xjustadev was already his DN404 collaborator. So the response team came partly from the same professional network that existed years before the exploit. Quit’s MEV wallet funded the rescue This is one of the most direct facts in the story. oSnipe operating wallet: 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E funded rescue wallet: 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 through: 0x48b1a7e82590456fd1511dad44248a911b6ec07b49606eb40841d1253b69a225 So Quit did not use a completely isolated security wallet. His commercial MEV infrastructure funded the incident-response wallet. That is not proof of criminal conduct. But it is a real mixing of commercial MEV infrastructure and security-response infrastructure. Then the rescue creates a donation stream A recovery contract was deployed: 0xa5F629Daf7F21364ED39f84bD730FF6571227648 Its code includes: recovery claims; Merkle proofs; checks that users revoked the vulnerable approval; NFT return logic. It also hard-codes: 0x840777f48fdd75c552793fd7d1429a93e0f978e4 which is: nftsaresafu.eth That wallet was funded by osnipe.eth. Quit publicly promoted it as the donation address associated with the rescue. So the same cluster becomes: oSnipe commercial MEV wallet → funds rescue and oSnipe commercial MEV wallet → funds donation wallet and recovery contract → embeds that donation wallet. That means the security rescue also generated reputational and potentially financial benefits for the same operator. That is a conflict people are entitled to understand. The bigger picture: If you strip away all the crypto jargon, this is what people should see: Quit has positioned himself in several places at once. He is close to the locks: smart-contract security. He is close to the marketplace: Yuga, ApeChain, Otherside. He is close to the lock manufacturer: Limit Break engineers and infrastructure. He runs a high-speed trading system: oSnipe. He is involved in a financial NFT product: FWAP. FWAP integrates another financial NFT market system: FWA / TokenWorks / Rhynotic. His MEV wallet configures Limit Break transfer permissions for FWAP-related infrastructure. And when Limit Break’s Payment Processor failed, he became one of the central responders. That is a remarkable concentration of roles.
145
Oh, you need an ELI5. Ok. The “random independent whitehat saves the day” version leaves out a large amount of relevant context. Quit was already embedded in the engineering, marketplace, MEV, security and financial-product ecosystem surrounding the protocols involved. His response to the exploit occurred through people and infrastructure with which he had pre-existing relationships. The easiest way to understand 0xQuit is this: He is not just “the guy who showed up after a hack.” He has spent years placing himself at the intersection of security, marketplaces, MEV, NFT trading infrastructure, Yuga, Limit Break-adjacent engineers, and financialized NFT protocols. That positioning is real and documentable. What is not established is that the entire network acted together criminally. Think of it like this. A normal independent security researcher is more like a locksmith: they inspect locks, tell you where the weaknesses are, and maybe help when somebody breaks in. Quit is closer to a locksmith who also: builds high-speed tools for getting through doors before other people; works for one of the biggest property owners in town; helps operate a financial business inside some of those buildings; invests alongside other security and engineering people; has previously written code with engineers who built the lock system; uses the lock company’s permission system in another business; and then becomes one of the main people responding when that lock system fails. That does not automatically mean he arranged the burglary. But it means he is inside a lot of the systems involved, not standing outside them. Start with oSnipe Quit founded @oSnipeNFT. oSnipe is an NFT MEV/sniping system. In simple terms, it is built to recognize profitable NFT transactions and compete to execute them faster or more effectively than ordinary users. Ordinary users like you. That means Quit has direct experience with: transaction ordering; private execution; paying builders/validators for priority; taking advantage of time-sensitive pricing differences; exploiting market inefficiencies. That is important because MEV is fundamentally about who gets to act first and who captures the value created by someone else’s transaction. So Quit is not merely a security person who understands how attackers work. He runs technology designed to exploit timing and execution advantages in markets. His operational oSnipe wallet is: 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet later funded the September 2026 Limit Break rescue wallet. So the same operational ecosystem used for his commercial MEV project was directly involved in the incident response. Quit already knew Limit Break engineers before this incident. This is one of the most important facts. In February 2024, Quit helped author DN404. Other contributors included: @0xjustadev @0xCygaar @optimizoor @PopPunkOnChain @AmadiMichaels @0xjustadev They are all associated with Limit Break engineering. So Quit and a Limit Break engineer were already writing smart-contract code together more than two years before the September 2026 exploit. That matters because when the hack later occurred and Quit says he contacted Limit Break, he was not reaching out to some company he had never dealt with before. He was contacting people inside an existing technical network. At almost the same time, Limit Break entered the Magic Eden/Yuga marketplace stack. In 2024, Limit Break’s Payment Processor technology was adopted for the Magic Eden/Yuga Ethereum marketplace. That is the same general contract family that became central to the 2026 exploit. Magic Eden later confirmed that old approvals to Payment Processor V2 remained active after it stopped using the processor in October 2024. Those old approvals are what left users exposed. So by early 2024: Quit was working with a Limit Break engineer. Limit Break was entering the Yuga/Magic Eden marketplace infrastructure. Quit had not yet officially joined Yuga. That timing is worth understanding. Then comes James Hall. James Hall was already a major engineering figure at Yuga. In July 2024, both Quit and James Hall appeared as investors in the same Ethos funding round. Then, a few months later, Quit joined Yuga as VP of Blockchain. So before Quit officially worked at Yuga, he and Yuga’s engineering leadership were already participating in the same investment network. Again, that does not mean wrongdoing. But it means there was already a professional/financial connection. Then Quit joins Yuga. After joining Yuga, Quit becomes responsible for blockchain strategy and ApeChain. James Hall continues leading engineering and later takes responsibility for Otherside. Then in February 2026 Hall publishes a technical guide for the Otherside marketplace. That guide explicitly says: the Otherside MarketplaceOrderRegistry is built on top of Limit Break Payment Processor V3. The V3 address is: 0x9a1D00000000fC540e2000560054812452eB5366 That is not some minor dependency. It is the settlement engine behind the marketplace. So now the relationship becomes: Quit → Yuga blockchain leadership James Hall → Yuga engineering / Otherside Otherside → Limit Break Payment Processor V3 That is the same Payment Processor family that later becomes part of the September incident. Guardian enters the picture too. Guardian audited Yuga’s NFT Shadows system. Guardian’s own case study prominently displays a testimonial from 0xQuit of Yuga Labs. Guardian also appears in the broader investor/security network around g8keep with Quit and other Solidity people. And later Guardian infrastructure was used for Limit Break AMM security work. The important thing is not that Guardian “caused” anything. It is that the same relatively small group of security engineers, auditors, investors and protocol builders repeatedly shows up around: Yuga; Limit Break; DN404; g8keep; Gaslite; marketplace infrastructure. FWAP is where it gets more operational. Quit is also involved with FWAP/FWAPHouse. This is important because FWAP is not merely a social association. There are wallet-level operational connections. The FWAPHouse deployer is: 0x3561b02bB427FB5aBA9AF0EA005b12A49246DF21 That wallet funded: 0xd7395e1d103837607a4ca9aa9389cbf688a06132 Then Quit’s oSnipe operating wallet: 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E used Limit Break’s Creator Token Transfer Validator V5: 0x721C008fdff27BF06E7E123956E2Fe03B63342e3 to add: 0xd7395e1d103837607a4ca9aa9389cbf688a06132 to validator list 13. That is a direct operational loop: FWAPHouse funds an address → oSnipe adds that address into Limit Break transfer-control infrastructure. That is much more significant than two people knowing each other. Limit Break’s Transfer Validator is essentially a programmable permission system for NFT transfers. It supports allowlists, authorizer lists, security levels and other transfer rules. So in plain English: A wallet from Quit’s MEV operation was configuring permissions inside a Limit Break transfer-control system for a wallet funded by Quit-associated FWAP infrastructure. That is exactly the kind of relationship people should understand. Then comes FWA and Rhynotic. FWAP later integrates Fake World Assets, or FWA. FWA is operated by @token_works, with @Rhynotic publicly involved. FWA is effectively a financialized NFT market mechanism where NFTs are paired with ETH backing and transactions occur through structured on-chain rules. Quit publicly discusses and explains FWA mechanics and FWAP’s integration with it. That creates another important combination: Rhynotic / TokenWorks → FWA financial mechanics FWAP → integrates FWA Quit → operates/explains FWAP Quit → also operates oSnipe MEV That matters because MEV becomes more valuable when transactions are predictable and involve pricing, pool state, backing levels, settlement or arbitrage. In very simple terms: If you know how a machine is going to move prices, and you also own a high-speed trading engine that can act before or after users, that creates a conflict that should be independently audited. That does not establish that he exploited FWA or FWAP users. But the technical ability and operational overlap are real. Now look at the September 2026 incident. The vulnerable contract was Limit Break Payment Processor V2: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 An attacker exploited it and stole 305 NFTs. Magic Eden says old user approvals remained active even though it stopped using V2 in 2024. Quit says more than 12 hours later @Boomskite alerted him. Quit investigated. Quit contacted Limit Break. Limit Break paused V3 where possible. V2 could not be paused. Quit says a defensive operation then moved 23,155 NFTs worth more than $5.7 million into custody. Who helped? Quit publicly credited: @0xjustadev @whiteoakkong @coffeedev Remember: @0xjustadev was already his DN404 collaborator. So the response team came partly from the same professional network that existed years before the exploit. Quit’s MEV wallet funded the rescue This is one of the most direct facts in the story. oSnipe operating wallet: 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E funded rescue wallet: 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 through: 0x48b1a7e82590456fd1511dad44248a911b6ec07b49606eb40841d1253b69a225 So Quit did not use a completely isolated security wallet. His commercial MEV infrastructure funded the incident-response wallet. That is not proof of criminal conduct. But it is a real mixing of commercial MEV infrastructure and security-response infrastructure. Then the rescue creates a donation stream A recovery contract was deployed: 0xa5F629Daf7F21364ED39f84bD730FF6571227648 Its code includes: recovery claims; Merkle proofs; checks that users revoked the vulnerable approval; NFT return logic. It also hard-codes: 0x840777f48fdd75c552793fd7d1429a93e0f978e4 which is: nftsaresafu.eth That wallet was funded by osnipe.eth. Quit publicly promoted it as the donation address associated with the rescue. So the same cluster becomes: oSnipe commercial MEV wallet → funds rescue and oSnipe commercial MEV wallet → funds donation wallet and recovery contract → embeds that donation wallet. That means the security rescue also generated reputational and potentially financial benefits for the same operator. That is a conflict people are entitled to understand. The bigger picture: If you strip away all the crypto jargon, this is what people should see: Quit has positioned himself in several places at once. He is close to the locks: smart-contract security. He is close to the marketplace: Yuga, ApeChain, Otherside. He is close to the lock manufacturer: Limit Break engineers and infrastructure. He runs a high-speed trading system: oSnipe. He is involved in a financial NFT product: FWAP. FWAP integrates another financial NFT market system: FWA / TokenWorks / Rhynotic. His MEV wallet configures Limit Break transfer permissions for FWAP-related infrastructure. And when Limit Break’s Payment Processor failed, he became one of the central responders. That is a remarkable concentration of roles.
4
2
10
1,681
Bring discovery BITCH
This is the problem grifting, if you do it too hard you may open yourself up for lawsuits. NFA NLA lol
3
3
571
I don’t have to defend myself. Either you understand the research or you don’t. I did the work. Now it’s up to you to understand it.
1
5
352
Stirred up the hornets nest, didn’t I? 🖕🏻😎🖕🏻
***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!*** The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY The public story around @0xQuit is usually reduced to one word: “whitehat.” That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role. The documented record shows that Quit is simultaneously: VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations. That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol. Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts. THE MEV BUSINESS Quit founded oSnipe. Its public description is direct: “Your personal MEV sniper. By @0xQuit.” One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9 A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report: oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth. MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately. That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement. Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it. The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles. THE WALLET IDENTITY LAYER Quit’s publicly attributable wallet history is broader than a single address. High-confidence Quit-linked addresses include: quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60 unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7 quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620 The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction. WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT By September 2026, Quit was positioned at the intersection of: MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response. The next posts show how that network formed before the exploit ever occurred. Sources nitter.net/oSnipeNFT twstalker.com/0xQuit/status/… etherscan.io/address/0x5c049… etherscan.io/address/0x862c9…
2
3
371
***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!*** The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY The public story around @0xQuit is usually reduced to one word: “whitehat.” That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role. The documented record shows that Quit is simultaneously: VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations. That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol. Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts. THE MEV BUSINESS Quit founded oSnipe. Its public description is direct: “Your personal MEV sniper. By @0xQuit.” One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9 A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report: oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth. MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately. That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement. Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it. The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles. THE WALLET IDENTITY LAYER Quit’s publicly attributable wallet history is broader than a single address. High-confidence Quit-linked addresses include: quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60 unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7 quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620 The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction. WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT By September 2026, Quit was positioned at the intersection of: MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response. The next posts show how that network formed before the exploit ever occurred. Sources nitter.net/oSnipeNFT twstalker.com/0xQuit/status/… etherscan.io/address/0x5c049… etherscan.io/address/0x862c9…
12
15
8,040
Anonymous Nobody retweeted
***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!*** The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY The public story around @0xQuit is usually reduced to one word: “whitehat.” That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role. The documented record shows that Quit is simultaneously: VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations. That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol. Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts. THE MEV BUSINESS Quit founded oSnipe. Its public description is direct: “Your personal MEV sniper. By @0xQuit.” One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9 A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report: oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth. MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately. That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement. Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it. The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles. THE WALLET IDENTITY LAYER Quit’s publicly attributable wallet history is broader than a single address. High-confidence Quit-linked addresses include: quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60 unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7 quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620 The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction. WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT By September 2026, Quit was positioned at the intersection of: MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response. The next posts show how that network formed before the exploit ever occurred. Sources nitter.net/oSnipeNFT twstalker.com/0xQuit/status/… etherscan.io/address/0x5c049… etherscan.io/address/0x862c9…
31
6
56
26,102
Come on. Attack me, motherfuckers. I know your bags depend on it. But I don’t give a fuck about your bags. And if you did, @0xQuit wouldn’t have ended up with them in his wallet. So shut the fuck up, read the thread, follow the trails, secure your shit, and stop believing cartoons on the internet you fucking dolts. I have way more to lose than you do by fighting what you refuse to even see. You’ll realize it way too late like you always do.
1
310
You think the MEV bot creator is a white hat after all the sandwich attacks you’ve been through?! LOL. OK. Send him money then. 🤣
2
6
298
If you don’t share this, I’ll assume that you’re either a bad actor, support bad actors, always want to be the one getting fucked, like seeing others get fucked, are a bot, don’t believe that a faceless online persona that says their hat is white would ever manipulate you, don’t care, or are on the take. In the words of John McAfee, “WAKE THE FUCK UP PEOPLE!”
***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!*** The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY The public story around @0xQuit is usually reduced to one word: “whitehat.” That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role. The documented record shows that Quit is simultaneously: VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations. That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol. Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts. THE MEV BUSINESS Quit founded oSnipe. Its public description is direct: “Your personal MEV sniper. By @0xQuit.” One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9 A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report: oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth. MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately. That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement. Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it. The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles. THE WALLET IDENTITY LAYER Quit’s publicly attributable wallet history is broader than a single address. High-confidence Quit-linked addresses include: quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60 unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7 quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620 The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction. WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT By September 2026, Quit was positioned at the intersection of: MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response. The next posts show how that network formed before the exploit ever occurred. Sources nitter.net/oSnipeNFT twstalker.com/0xQuit/status/… etherscan.io/address/0x5c049… etherscan.io/address/0x862c9…
4
408
Anonymous Nobody retweeted
Masterpiece look into the recent NFT Magic Eden Exploit and the shady “relationships and network of the “whitehat rescue”. Much like I’ve found, with TheDAO exploit, several people on Seal911, and most major exploits in Crypto since inception, the Whitehats are at best Greyhats, but often Blackhats masked as Whitehats.
***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!*** The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY The public story around @0xQuit is usually reduced to one word: “whitehat.” That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role. The documented record shows that Quit is simultaneously: VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations. That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol. Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts. THE MEV BUSINESS Quit founded oSnipe. Its public description is direct: “Your personal MEV sniper. By @0xQuit.” One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9 A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report: oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth. MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately. That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement. Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it. The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles. THE WALLET IDENTITY LAYER Quit’s publicly attributable wallet history is broader than a single address. High-confidence Quit-linked addresses include: quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60 unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7 quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620 The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction. WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT By September 2026, Quit was positioned at the intersection of: MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response. The next posts show how that network formed before the exploit ever occurred. Sources nitter.net/oSnipeNFT twstalker.com/0xQuit/status/… etherscan.io/address/0x5c049… etherscan.io/address/0x862c9…
7
17
2,809
This won’t be the end. I have a long list of people I suspect are here to harm the space, and I’m going to expose as many of them as possible. Too often do these people get to operate in the shadows, make tons of money off of unsuspecting people, and get away with it all. And you fuckers always trust them blindly.
***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!*** The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY The public story around @0xQuit is usually reduced to one word: “whitehat.” That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role. The documented record shows that Quit is simultaneously: VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations. That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol. Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts. THE MEV BUSINESS Quit founded oSnipe. Its public description is direct: “Your personal MEV sniper. By @0xQuit.” One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9 A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report: oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth. MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately. That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement. Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it. The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles. THE WALLET IDENTITY LAYER Quit’s publicly attributable wallet history is broader than a single address. High-confidence Quit-linked addresses include: quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60 unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7 quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620 The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction. WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT By September 2026, Quit was positioned at the intersection of: MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response. The next posts show how that network formed before the exploit ever occurred. Sources nitter.net/oSnipeNFT twstalker.com/0xQuit/status/… etherscan.io/address/0x5c049… etherscan.io/address/0x862c9…
6
1
12
1,184
Maybe @cryptohydrate and @MrSegovia should read this thread.
2
696
Feel free to send me ETH here or cash here on X. 0x6B85c6E03A939Cb37942F882eE2310E5Af3642BB I worked my ass off on this so you could know what is going on around you and who you’re really dealing with in this space. I encourage others to use my research to dig further and publish their findings. Goodnight.
1
2
724
And for @digitalcolle and @0xQuit: Did either of you, or any wallet/project you control, have any financial relationship with any wallet that bought MrDigital’s stolen NFTs or received the WETH proceeds? Yes or no?
695
@0xQuit Since your oSnipe operating wallet funded the Limit Break recovery wallet, and oSnipe/FWAP infrastructure also uses Limit Break transfer-control contracts, can you answer these directly: • Had you ever communicated or transacted with MrDigital / digitalcollection.eth / mrdigital.eth before the exploit? • Did any oSnipe, FWAP, Yuga, Limit Break, or affiliated wallet buy any of the 50 Otherdeeds or 10 Meebits after they were stolen? • Did any wallet you control receive MEV, builder profit, arbitrage, fees, or other value from transactions related to those liquidations? • When did you first learn the exact vulnerability in Payment Processor V2? • When did Limit Break learn? • Did anyone in your professional network trade affected assets before public disclosure? • Will you publish the wallets used by everyone involved in the recovery so the public can independently rule out financial conflicts?
3
5
1,217
@digitalcolle You’ve said hackers stole 50 Otherdeeds and 10 Meebits from you, then immediately sold them into WETH bids, and that you don’t want OpenSea to block the NFTs because the downstream buyers were “honest.” Those assets were worth hundreds of thousands of dollars, so I have some straightforward questions: How do you know the buyers were “honest”? Were those WETH bids already standing before the exploit? Please publish the buyer wallets and the original bid timestamps. Do you personally know, have you previously transacted with, or have you had any business relationship with any of the buyers who received those 60 NFTs? Have any of those buyer wallets ever interacted with @0xQuit, @oSnipeNFT, FWAP/FWAPHouse, TokenWorks/FWA, @limitbreak, or wallets associated with those projects? Where did the WETH paid for your stolen NFTs go after the sales? Have you traced it? If so, publish the complete wallet path. Have you filed a police report, contacted law enforcement, or taken any steps to recover the WETH proceeds from the attacker? Have you received, or been promised, any reimbursement, compensation, private settlement, replacement assets, fee waiver, allocation, or other consideration related to this loss? Did you communicate with @0xQuit, @MagicEden, @limitbreak, or anyone associated with them before the exploit became public? If yes, when? Had you ever communicated or done business with @0xQuit before September 24, 2026? Were any of your wallets using oSnipe, FWAP/FWAPHouse, FWA/TokenWorks, or Limit Break infrastructure before the exploit? Will you publish the exact 60 token IDs and sale transactions so independent researchers can verify that every buyer was an unrelated pre-existing bidder? If the explanation is exactly what you say it is, all of this should be straightforward to verify on-chain.
2
744