A bug in Restrict Break’s Cost Processor V2 was exploited to steal NFTs earlier than safety researchers recognized the problem and launched a whitehat rescue operation, as reported by 0xQuit, additionally identified publicly as Give up, the pseudonymous vice chairman of blockchain at Yuga Labs.
At 9AM EST at this time any person abused a bug in Cost Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Determined Apewives.
It wasn’t till over 12 hours later that any person reported it to me, and upon digging in I spotted that an important many NFTs have been topic to the… pic.twitter.com/Vue8TUyMD2
— Give up (@0xQuit) September 25, 2026
In response to Give up, the exploit initially affected 10 Meebits, 50 Otherdeeds, 10 World of Girls NFTs and 235 Determined ApeWives, earlier than researchers decided that many extra NFTs have been susceptible to the identical assault.
Restrict Break shortly paused Cost Processor V3 after being alerted, however V2 couldn’t be paused, requiring affected property to be moved by a whitehat operation.
An identical vulnerability was additionally discovered on ApeChain, the place some property accredited to V3 wanted to be secured. In whole, 23,155 NFTs price greater than $5.7 million have been rescued, whereas a associated exploit that might be used to steal WETH left 660 WETH in danger and unrecovered.
Magic Eden mentioned it stopped utilizing Cost Processor V2 in October 2024 and shut down its EVM market within the first quarter of 2026, including that no reside Magic Eden listings have been affected.
{The marketplace} mentioned NFTs listed on its EVM platform between roughly February and October 2024 should be uncovered and urged customers to revoke affected “accredited for all” permissions.

