Skip to content
Est. MMXXVIVol. VI · № 343RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 342Bridge Exploit

Payy Network Rollup Bridge Exploit

An attacker exploited Payy Network's Ethereum rollup contract with a malicious verifyRollup transaction, draining roughly $1.83 million in USDC and forcing the payments platform offline.

Date
Chain(s)
Status
Funds Stolen

On September 24, 2026, Payy Network — a privacy-focused payments platform whose rollup settles to Ethereum — was exploited for approximately $1.83 million in USDC after an attacker abused the contract that bridges its network to mainnet.

What happened

At 04:21 UTC, the attacker submitted a malicious verifyRollup transaction, confirmed at block 26044909, against Payy's Ethereum rollup contract. That contract functions as the bridge between Payy's off-chain network state and Ethereum settlement, and the crafted call let the attacker drain the contract's full USDC balance — about $1.83 million. Blockchain investigators at Specter Investigation traced the stolen USDC through the Railgun privacy protocol, where it was converted into roughly 683 ETH and fanned out across multiple addresses to frustrate tracing. Payy confirmed the incident publicly and suspended the entire platform, taking deposits, withdrawals, transfers, and card payments offline while it worked with law enforcement.

Aftermath

Payy said it halted all network operations to prevent further loss and was cooperating with cybersecurity professionals and authorities. The stolen funds, laundered through Railgun and split across wallets, were not recovered as of late September 2026, so the status here is stolen. Notably, this was not Payy's first security scare in 2026 — the project had earlier disclosed a critical flaw in its zero-knowledge circuit logic, underscoring the difficulty of hardening a privacy-preserving payment stack.

Why it matters

A rollup's bridge contract is the single point where off-chain claims become on-chain money; if its proof-verification path can be tricked, the entire settlement guarantee collapses. Payy joins a busy week of bridge-class failures — the Meter Passport unbacked mint and the Nomic nBTC double-spend — that share one root cause: a settlement layer accepting a forged or malformed proof as if it were valid. Rigorous verification of every bridge and rollup message, not just the happy path, remains the hardest and most consequential engineering task in the space.

Sources & on-chain evidence

  1. [01]cryptobriefing.comhttps://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/
  2. [02]protos.comhttps://protos.com/defi-hack-attack-three-exploits-snatch-11m-in-a-single-day/
  3. [03]cryptotimes.iohttps://www.cryptotimes.io/2026/09/24/1-83-million-in-usdc-leaves-payy-networks-ethereum-rollup-contract/

Related filings