# protocol exploit — X 热门讨论 (2026-09-26 16:48 UTC)
## @WuBlockchain (Wu Blockchain) · 09-26 13:52 · ♥74 ↻16 💬18 Bitget CEO Gracy Chen Formally Asks THORChain to Reject Transactions from Exploiter Addresses
On-chain tracking platform MistTrack, an arm of SlowMist, pointed out that following an earlier exploit of Bybit where nearly $1.2 billion in stolen funds was routed through THORChain for cross-chain transfers, proceeds from the recent Bitget security incident are once again flowing into THORChain for asset swaps and cross-chain bridging. MistTrack stated that the hacker addresses had already been publicly flagged and actively tracked across the industry. With the protocol continuing to facilitate large-scale cross-chain swaps despite knowing the assets originated from a publicly known major exploit, MistTrack argued that decentralization should not serve as an excuse for handling known stolen funds, and that the industry needs to seriously discuss what responsibility THORChain should bear in such scenarios.
In response, Bitget CEO Gracy Chen stated that the associated attacker addresses have been made public and remain under active surveillance, formally asking THORChain to reject transactions originating from these addresses. She noted that decentralization is a design principle rather than a shield for facilitating the movement of known stolen funds. https://x.com/WuBlockchain/status/2103845081547780182
## @AFuckingNobody (Anonymous Nobody) · 09-26 09:41 · ♥38 ↻6 💬22 ***PLEASE LIKE AND SHARE! THIS IS IMPORTANT!***
The “Whitehat,” the MEV Bot, and the Marketplace: Mapping 0xQuit’s Overlapping Roles in NFT Security
POST 1/7 — THE “WHITEHAT” LABEL IS ONLY ONE PART OF THE STORY
The public story around @0xQuit is usually reduced to one word: “whitehat.”
That label came from Quit himself and from projects that credited him with security rescues. It is only one part of his public role.
The documented record shows that Quit is simultaneously:
VP of Blockchain at @yugalabs, overseeing ApeChain technical development and strategy; founder of @oSnipeNFT, an NFT MEV/sniping product; a Solidity developer and auditor; an active NFT trader and market participant; a protocol operator around FWAP/FWAPHouse; an investor in crypto infrastructure projects; a prior code collaborator with a senior @limitbreak engineer; a participant in multiple exploit-response operations.
That combination matters because the September 2026 Limit Break incident was not an encounter between a detached outside security researcher and a completely unrelated protocol.
Quit’s professional, financial and technical network already overlapped with Limit Break personnel, Yuga engineering, Guardian security, NFT market infrastructure and projects that use Limit Break transfer-control contracts.
THE MEV BUSINESS
Quit founded oSnipe. Its public description is direct:
“Your personal MEV sniper. By @0xQuit.”
One deterministic AutoSniper deployment used across EVM networks is: 0x000000000000feA5F4B241F9E77B4D43B76798a9
A central oSnipe operational wallet is: osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E
That wallet repeatedly interacts with AutoSniper infrastructure and later appears in several branches of this report:
oSnipe MEV execution; FWAP/FWAPHouse operations; Limit Break Creator Token Transfer Validator configuration; funding the September 2026 rescue wallet; funding nftsaresafu.eth.
MEV is transaction-ordering economics. An MEV system can compete to get a transaction executed first, backrun another transaction, capture arbitrage created by a user, pay builders or validators for priority, or route execution privately.
That is especially important in NFTs because a profitable opportunity can exist for only seconds and because value can be created by stale listings, floor changes, pool rebalancing, liquidation-like mechanics and user settlement.
Quit therefore does not merely study MEV as a security researcher. He operates infrastructure designed to capture it.
The central public-interest issue is whether an actor with security information, market infrastructure, protocol operations and transaction-ordering capability has adequate separation and independent oversight between those roles.
THE WALLET IDENTITY LAYER
Quit’s publicly attributable wallet history is broader than a single address.
High-confidence Quit-linked addresses include:
quit.q00t.eth 0xC218D847a18E521Ae08F49F7c43882b6d1963c60
unfuhquittable.eth 0x5C04911bA3a457De6FA0357b339220e4E034e8F7
quit.tryptic.eth 0x84B966BECF1c5c788b59Ce4Aa4Ab0F7a6e827Baa
osnipe.eth 0x7D79Bd0E4B3dC90665A3ed30Aa6C6c06c89D224E
The relationship is not based only on ENS names. quit.q00t.eth directly funded unfuhquittable.eth, including a 100 ETH transfer: 0xaab3dcd04ac633459f18626064222c46d155df38955aa200e3b45c5e0c3a41fd
quit.tryptic.eth also transacted into the same wallet cluster and is independently connected to the q00t project as creator of the q00tants contract: 0x862c9b564fbdd34983ed3655aa9f68e0ed86c620
The q00t namespace itself contained many third-party subdomains, so a q00t ENS name alone is not sufficient attribution. The useful evidence is direct funding, contract creation and recurring operational interaction.
WHY THIS MATTERS BEFORE WE EVEN REACH THE EXPLOIT
By September 2026, Quit was positioned at the intersection of:
MEV execution; NFT market infrastructure; Yuga/ApeChain; FWAP/FWA-style NFT financial products; Limit Break transfer controls; security auditing; and incident response.
The next posts show how that network formed before the exploit ever occurred.
Sources https://t.co/rggkrnbuTV https://t.co/NN0koRnslA https://t.co/UPSuYS7EHe https://t.co/QVJuphgeNA https://x.com/AFuckingNobody/status/2103781925047722493