At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives.
It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the same exploit.
I got in touch with the team over at LimitBreak and they quickly paused Payment Processor V3, which was subject to the same exploit. Unfortunately, V2 was not pausable, so the only path towards protecting affected assets was to run a whitehat operation.
Similarly, V3 on ApeChain is temporarily in a state where it cannot be paused, so ApeChain assets approved to V3 needed to be saved as well.
All in all, we rescued 23,155 NFTs worth north of $5.7M USD.
We later discovered that a similar exploit could be used in reverse to steal WETH. 660 WETH was at risk, which we unfortunately were not fast enough to recover. Apologies to those affected.
Shout out to
@Boomskite for flagging the initial exploit tx to me, and
@coffeedev @0xjustadev and
@whiteoakkong for acting quickly and assisting with the recovery.
All NFTs are safely relocated. Soon, owners will be able claim them back after revoking the exploitable approvals.
Addresses to revoke below.