Payy Freezes Network After $1.83M Exploit
Payy Network halted deposits, withdrawals, transfers & card transactions after an Ethereum bridge exploit drained about $1.83M in USDC.
Payy Network has paused its entire payments network after an attacker exploited its Ethereum bridge and drained approximately $1.83 million in USDC, adding another bridge related incident to Ethereum’s growing list of infrastructure security failures in 2026.
The exploit occurred on September 24 at approximately 04:21 UTC, when a transaction interacted with Payy’s RollupV1 contract on Ethereum and moved around 1.832 million USDC out of the bridge. Payy later confirmed that the bridge had been exploited and that its full balance had been drained. triggers-290m-crisis-across-defi/) earlier this year.
$1.83M USDC Leaves Payy’s Ethereum Rollup
Onchain records indicate that the exploit transaction called Payy’s verifyRollup function and removed approximately 1,832,149 USDC from the contract at:0x367C1eAF14AA06b78ce76bd0243297de79d85270.
The transaction was included in Ethereum block 26,044,909 at roughly 04:21 UTC. Around 1.828 million USDC was transferred to the main recipient address, while the remaining funds were distributed through two smaller transfers. The combined transfers accounted for almost the entire balance removed from the rollup contract.
Security firm PeckShield later reported that the attacker had converted the stolen USDC into approximately 683.38 ETH, with most of the ETH subsequently split between three addresses. Public incident tracking also indicates that the attacking address received initial transaction funding through Railgun before the exploit.
Fund conversion following an exploit is a familiar pattern across DeFi incidents. Attackers often move stablecoins into more liquid crypto assets before separating funds across multiple addresses.
Cross chain systems have become particularly important security targets because bridge contracts frequently custody large pools of assets while depending on separate validation or messaging infrastructure.
The problem became especially visible during the KelpDAO LayerZero exploit, where weaknesses around cross chain verification ultimately pushed KelpDAO to move its rsETH bridge infrastructure away from LayerZero. EtherWorld’s broader review of April’s $635 million DeFi exploit wave similarly identified cross chain infrastructure as one of the recurring attack surfaces across major incidents.
Payy Pauses Deposits, Withdrawals & Card Transactions
Payy confirmed the breach several hours after the transaction and announced that activity across the network had been temporarily suspended. The pause covers:
- Deposits
- Withdrawals
- Transfers
- Card transactions
Payy said its investigation is ongoing and that the team is following its incident response procedures. External reports also indicate that law enforcement and outside security organizations have been contacted as investigators assess the attack.
Similar containment strategies have appeared repeatedly following infrastructure breaches. When a flaw affected Gnosis Pay earlier this year, the protocol halted parts of its infrastructure while investigating the issue and later committed to compensating affected users.
EtherWorld covered the episode in Gnosis Pay Exploit Hits Delay Module, Users Reimbursed. Taiko also chose operational containment when its state verification mechanism was compromised.
As detailed in Taiko Halts Network After Security Breach, proposers temporarily stopped block production while developers investigated whether the network’s bridge security assumptions could still be trusted. Even non exploit outages have required similar caution.
EtherWorld reported how Base temporarily halted block production after an invalid block, temporarily disrupting deposits, withdrawals & other infrastructure despite there being no confirmed theft of funds.
Questions Grow Around Rollup Verification
Early analysis from security researcher ExVulSec focused on the verifyRollup execution path. According to the researcher, the suspicious withdrawal appeared inside a batch submitted through Payy’s prover infrastructure and accompanied by a validator signature.
The researcher argued that Payy’s publicly available circuits should not normally allow a user to generate the specific withdrawal involved in the incident. That has led to several possible explanations being discussed, including compromise of the prover or validator setup or insufficient verification of which inner circuit was actually being proven.
These remain preliminary hypotheses rather than Payy’s confirmed root cause. The onchain transaction proves that the withdrawal was accepted and processed, but it does not by itself establish how the attacker gained the ability to submit it.
The risks became particularly visible when Taiko’s state verification mechanism was compromised. In that case, the concern extended beyond a single contract because unreliable state verification could also affect bridges relying on that state.
Syscoin faced a related validation problem when a faulty bridge validation process allowed unauthorized tokens to be created. EtherWorld covered how the Syscoin bridge exploit resulted in 5 billion illegitimate SYS tokens.
Access control failures can create similar systemic consequences without exploiting cryptography itself. Earlier this year, a compromised private key enabled an attacker to create roughly $80 million in unbacked tokens during the Resolv exploit.
A more recent Ethereum incident showed another variation of the same problem. In the $7.73M rsETH Safe exploit, the underlying Safe multisig itself was not compromised. Instead, an authorized external module created the path attackers used to move funds.
Another Warning for Ethereum’s Bridge Security
Bridges and rollups sit at the boundary between Ethereum settlement and systems that maintain their own execution, proof or validation infrastructure. Users depend on those systems to correctly determine when assets can leave custody.
EtherWorld previously highlighted the same concern after a vulnerability in Hyperbridge’s Ethereum gateway affected bridged DOT. In Hyperbridge Flaw Hits Polkadot's DOT on Ethereum, the underlying Polkadot network remained unaffected while the gateway infrastructure connecting assets to Ethereum became the source of risk.
The broader scale of the problem can also be seen in EtherWorld’s April 2026 DeFi security review, which documented 28 incidents and more than $635 million in losses across bridge, protocol, oracle & user level vulnerabilities.
Projects such as TheDAO Security Fund are directing capital toward smart contract security, monitoring, incident response, wallet protection & infrastructure research. EtherWorld has also explored the broader funding model in Securing Ethereum Together: Giveth & TheDAO’s QF Approach.
Its team must determine exactly how the unauthorized withdrawal passed through the rollup verification process, establish whether any other infrastructure was compromised, assess whether users suffered additional exposure & provide a safe path toward restoring network operations. At the time of writing, Payy has not published a complete technical post mortem or announced when deposits, withdrawals, transfers & card transactions will resume.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- Verus Ethereum Bridge Exploit Drains $11.58M
- KelpDAO Exploit Triggers $290M Crisis Across DeFi
- KelpDAO Exits LayerZero After Massive $292M Exploit
- April 2026 Worst for DeFi: Over $635M Lost in Exploits
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.