{"investigation":{"slug":"paid-network","entity_name":"PAID Network","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"PAID Network is an Ethereum-based DeFi launchpad and legal-contract protocol whose native PAID token suffered a catastrophic infinite mint exploit on March 5, 2021, resulting in approximately 59.5 million tokens being minted and ~2,040 ETH (~$3 million at the time) extracted before the team intervened. Significant on-chain evidence and community investigators raised allegations that the attack was an insider job or was enabled by gross negligence over a known vulnerability, though the team maintained it was an external private-key compromise. The token has since declined over 99% from its all-time high and retains a negligible market capitalization as of 2025-2026.","sections":[{"content":"On March 5, 2021, at approximately 18:07 UTC, PAID Network's smart contract was exploited in what the team described as an infinite mint attack. The attacker minted 59,471,745.571 PAID tokens — nearly doubling the existing supply — and proceeded to sell 2,501,203 of those tokens on Uniswap, netting approximately 2,040.4339 ETH, valued at roughly $3 million at the time. The team pulled Uniswap liquidity approximately 40 minutes after the exploit was detected, limiting further token dumps. The PAID token price declined between 85% and 92% within hours of the attack.\n\nAccording to the team's postmortem published on March 7, 2021, the attack was executed via compromise of the private key belonging to the original contract deployer wallet. The attacker used that key to call the contract's proxy upgrade function, replacing the legitimate contract with a malicious version that enabled burning of existing supply and minting of arbitrary new tokens. The team stated they found 'no reason to think' the key leak was malicious in origin, attributing it to an accidental exposure.\n\nOn-chain data examined by community investigators, including the @WARONRUGS Twitter account, showed that PAID's deployer contract transferred ownership of the proxy contract to a new wallet shortly before the mint — a transaction sequence that critics argued implied internal coordination rather than a purely external intrusion. Nick Chong of Parafi Capital noted publicly that the deployer transferred ownership to the attacker's wallet immediately before the minting event, a pattern consistent with either a deliberate insider action or a catastrophic operational security failure.\n\nThe stolen funds were never recovered. The attacker's wallet address (0x18738290af1aaf96f0acfa945c9c31ab21cd65be) retained the unconverted PAID tokens.","heading":"March 2021 Infinite Mint Exploit","sources":[{"url":"https://paidnetwork.medium.com/paid-network-attack-postmortem-march-7-2021-9e4c0fef0e07","name":"paidnetwork.medium.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2021/03/05/paid-network-exploit-mints-attacker-60m-tokens-report/","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-paid-network-hack-march-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.theblock.co/amp/linked/97411/paid-network-token-minting-exploit-eth","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.altcoinbuzz.io/finance-and-funding/real-exploit-or-rug-pull-paid-network-attack/","name":"altcoinbuzz.io","type":"other","credibility":3}],"severity":"medium"},{"content":"A substantial portion of the crypto community alleged that the March 2021 exploit was an insider job or rug pull rather than an external hack. The primary evidence cited was behavioral and on-chain:\n\n1. Pre-exploit warning ignored: In January 2021, the @WARONRUGS account publicly warned that PAID's deployer address retained the ability to mint arbitrary tokens at any time, without multisignature protections. This warning was not acted upon by the team, and the exact vulnerability flagged was subsequently exploited.\n\n2. Ownership transfer sequence: On-chain records showed the PAID deployer wallet transferred proxy ownership to an intermediary wallet shortly before the malicious contract was deployed and the mint executed. Critics argued this sequential ownership transfer is more consistent with deliberate insider action than an external attacker independently compromising and then using a private key.\n\n3. Mint function architecture: Community investigators noted that infinite mint capabilities must be deliberately programmed into a contract; an external attacker cannot introduce new smart contract logic unless they control the upgrade key. This meant that whoever controlled the deployer key — a member of the team or someone with direct access — was the proximate actor.\n\n4. Ivan on Tech connection: Allegations surfaced on Publish0x and elsewhere that popular YouTube influencer Ivan on Tech received PAID tokens as undisclosed compensation for promoting the project to his large audience. These allegations were not substantiated by court filings or regulatory action, and are considered low-confidence claims based primarily on community speculation and Tier 3 sources.\n\nThe PAID team denied any insider involvement in their postmortem, stating the key leak was accidental and not malicious. They engaged security firms including Cipherblade, Parsiq, and CertiK in the aftermath. No law enforcement action, court filing, or regulatory determination has been publicly issued confirming insider involvement as of the date of this report.","heading":"Insider Job Allegations and On-Chain Evidence","sources":[{"url":"https://www.altcoinbuzz.io/finance-and-funding/real-exploit-or-rug-pull-paid-network-attack/","name":"altcoinbuzz.io","type":"other","credibility":3},{"url":"https://paidnetwork.medium.com/paid-network-attack-postmortem-march-7-2021-9e4c0fef0e07","name":"paidnetwork.medium.com","type":"other","credibility":3},{"url":"https://www.publish0x.com/cryptoinvesting/paid-network-rugs-investors-lose-dollar-100m-ivan-on-tech-im-xykovnx","name":"publish0x.com","type":"other","credibility":3},{"url":"https://beincrypto.com/paid-network-releases-exploit-post-mortem/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The attack exposed fundamental security deficiencies in PAID Network's smart contract architecture. At the time of the exploit, control over the PAID token contract's upgrade function was vested in a single externally owned account (EOA), meaning one compromised or misused private key was sufficient to deploy a malicious contract replacement. This is considered a severe architectural risk in DeFi, as it creates a single point of failure that negates smart contract auditability.\n\nNotably, PAID Network had commissioned a security audit prior to the exploit. The audit reportedly reviewed contract code but did not surface the centralized key management risk as a critical finding — or if it did, the risk was not remediated. The @WARONRUGS account's January 2021 warning specifically identified the single-owner mint capability as a threat vector two months before the attack.\n\nFollowing the exploit, PAID moved contract governance to a multisignature wallet structure, requiring multiple authorized sigers for critical operations such as contract upgrades. This is the industry-standard mitigation for such risks. The failure to implement multisig from inception, combined with the disregard of a public pre-exploit warning, is viewed by security researchers as gross operational negligence at minimum.","heading":"Key Management Failures and Security Posture","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-paid-network-hack-march-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://paidnetwork.medium.com/paid-network-attack-postmortem-march-7-2021-9e4c0fef0e07","name":"paidnetwork.medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/paid-network-releases-exploit-post-mortem/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, PAID Network executed a token relaunch (PAID v2), deploying new smart contracts and taking a snapshot of token holdings at a point just before the attack. All v1 token holders received equivalent v2 tokens based on that snapshot. Users who purchased PAID tokens during the exploit window — in the hours immediately following the attack — received compensation from the PAID staking rewards pool, calculated at the dollar value of their v1 purchases.\n\nPAID Network also issued what it called a 'Strong-Hands bonus' of a $100 allocation on its Ignition launchpad to users who did not sell during the exploit, and a 'Lucky 7 bonus' of 10% additional PAID tokens for holders who did not move their tokens for seven weeks post-relaunch.\n\nGate.io, a centralized exchange that had listed the token, separately announced a compensation program for its users affected by the hack. The relaunch was criticized by some community members for being insufficiently transparent and for not fully addressing the losses of holders who were unable to sell during the price collapse before liquidity was pulled.","heading":"Token Relaunch and Compensation","sources":[{"url":"https://paidnetwork.medium.com/paid-v2-token-faq-cc6b7ab60907","name":"paidnetwork.medium.com","type":"other","credibility":3},{"url":"https://www.gate.com/announcements/article/20461/Important-announcement-regarding-compensation-for-PAID-Network-hack-victims-Gate.io-compensation-program","name":"gate.com","type":"other","credibility":3},{"url":"https://beincrypto.com/paid-network-rewards-community-for-support-during-hack/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"PAID Network was founded and led by Kyle Chasse (also spelled Chassé), who served as CEO. Chasse had prior experience as a serial entrepreneur and blockchain investor, including founding Master Ventures, a blockchain venture studio that incubated PAID Network. He previously served as COO of a project called Credits and had earlier ventures including a Bitcoin-based lottery (World Super Lotto) dating to 2013.\n\nChasse was the public face of PAID Network before and after the exploit, posting public statements and conducting AMAs explaining the team's response. No criminal charges, civil lawsuits, or regulatory enforcement actions against Chasse personally have been identified in public records as of the date of this report. The insider allegations against team members remain unproven and based on circumstantial on-chain evidence and community speculation.","heading":"Leadership and Background","sources":[{"url":"https://theorg.com/org/paid-network/org-chart/kyle-chasse","name":"theorg.com","type":"other","credibility":3},{"url":"https://medium.com/theamaroom/paid-network-with-kyle-chasse-ama-t-me-amaroom-8f28aa4045bf","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The PAID token reached its all-time high of approximately $6.38 on February 18, 2021, shortly before the exploit. Following the March 2021 attack and subsequent relaunch, the token experienced a sustained multi-year decline. By January 2024, PAID traded at approximately $0.37. By January 2025 it had fallen to approximately $0.093, and by early 2026 the token traded at approximately $0.00008–$0.00023 USD — a decline of over 99.99% from its all-time high.\n\nAs of early 2026, PAID Network's market capitalization was approximately $53,000–$54,000 USD with minimal daily trading volume (reported as low as $1.98 in 24-hour volume on some days). The project ranks approximately #7,022 on CoinGecko by market cap. The Ignition launchpad reportedly facilitated over $35 million in capital across approximately 110 investments during its operational period, though the platform's current activity level is negligible based on token liquidity metrics.\n\nPAID Network has since rebranded to 'PAID' and migrated to a new contract, though this has not materially affected the token's downward trajectory.","heading":"Token Performance and Current Status","sources":[{"url":"https://www.coingecko.com/en/coins/paid-network","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/paid-network/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://chainbroker.io/projects/paid-network/","name":"chainbroker.io","type":"other","credibility":3}],"severity":"medium"},{"content":"No SEC enforcement action, CFTC action, DOJ prosecution, or civil lawsuit referencing PAID Network as an entity has been identified in publicly available records as of the date of this report. The project has not appeared in SEC EDGAR filings as a registered or enforcement subject. No court filings have been identified linking the entity or its principals to fraud-related proceedings.\n\nThe absence of regulatory action does not constitute a finding of legitimacy; it reflects the general pattern of crypto exploit cases from 2021, where enforcement resources were limited and jurisdictional questions unresolved. The insider allegations, if substantiated, could potentially implicate securities fraud statutes depending on jurisdiction and token classification, but no such determination has been made publicly.","heading":"Regulatory and Legal Record","sources":[{"url":"https://www.sec.gov/newsroom/press-releases/2024-95","name":"sec.gov","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-10","event":"PAID Network launches; PAID token introduced as governance and utility token for a DeFi legal-contract and launchpad protocol founded by Kyle Chasse via Master Ventures.","source":"","date_original":"2020-10-01"},{"date":"2021","event":"The @WARONRUGS Twitter account publicly warns that PAID's deployer address retains the ability to mint unlimited PAID tokens without multisignature controls, identifying the exact vulnerability later exploited.","source":"","date_original":"2021-01-01"},{"date":"2021-02-18","event":"PAID token reaches its all-time high of approximately $6.38 USD.","source":""},{"date":"2021-03-05","event":"At approximately 18:07 UTC, the PAID smart contract is exploited. The attacker mints 59,471,745.571 PAID tokens using a compromised (or insider-controlled) deployer private key. 2,501,203 tokens are sold on Uniswap for ~2,040 ETH (~$3M). The PAID token price drops 85-92%. The team pulls Uniswap liquidity approximately 40 minutes after the attack is detected.","source":""},{"date":"2021-03-07","event":"PAID Network publishes its attack postmortem, attributing the exploit to an accidentally compromised private key and denying insider involvement. The team announces a token relaunch (v2) based on a pre-exploit holdings snapshot.","source":""},{"date":"2021-03-08","event":"Gate.io announces a separate compensation program for its users affected by the PAID Network hack.","source":""},{"date":"2021-04","event":"PAID Network launches its Ignition IDO launchpad. AIOZ Network is among the first projects to hold an IDO on the platform.","source":"","date_original":"2021-04-01"},{"date":"2021-05","event":"PAID Network migrates to v2 token contracts with multisignature governance controls implemented. Multiple additional IDO projects launch on Ignition through mid-2021.","source":"","date_original":"2021-05-01"},{"date":"2024","event":"PAID token trades at approximately $0.37, down dramatically from its 2021 all-time high.","source":"","date_original":"2024-01-01"},{"date":"2025","event":"PAID token trades at approximately $0.093, a further ~75% decline from January 2024 levels.","source":"","date_original":"2025-01-01"},{"date":"2026","event":"PAID token trades at approximately $0.00008–$0.00023 USD with negligible market capitalization (~$54,000) and minimal daily trading volume, representing a decline of over 99.99% from its all-time high.","source":"","date_original":"2026-01-01"}],"sources_used":[{"url":"https://paidnetwork.medium.com/paid-network-attack-postmortem-march-7-2021-9e4c0fef0e07","name":"paidnetwork.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/markets/2021/03/05/paid-network-exploit-mints-attacker-60m-tokens-report/","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-paid-network-hack-march-2021","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260121043343/https://www.halborn.com/blog/post/explained-the-paid-network-hack-march-2021","credibility":3,"archive_timestamp":"2026-01-21T04:33:43+00:00"},{"url":"https://www.theblock.co/amp/linked/97411/paid-network-token-minting-exploit-eth","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.altcoinbuzz.io/finance-and-funding/real-exploit-or-rug-pull-paid-network-attack/","name":"altcoinbuzz.io","type":"other","archive_url":"https://web.archive.org/web/20260829200219/https://www.altcoinbuzz.io/category/crypto-news","credibility":3,"archive_timestamp":"2026-08-29T20:02:19+00:00"},{"url":"https://www.publish0x.com/cryptoinvesting/paid-network-rugs-investors-lose-dollar-100m-ivan-on-tech-im-xykovnx","name":"publish0x.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://beincrypto.com/paid-network-releases-exploit-post-mortem/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://paidnetwork.medium.com/paid-v2-token-faq-cc6b7ab60907","name":"paidnetwork.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.gate.com/announcements/article/20461/Important-announcement-regarding-compensation-for-PAID-Network-hack-victims-Gate.io-compensation-program","name":"gate.com","type":"other","archive_url":"https://web.archive.org/web/20260830204452/https://www.gate.com/announcements/article/20461/Important-announcement-regarding-compensation-for-PAID-Network-hack-victims-Gate.io-compensation-program","credibility":3,"archive_timestamp":"2026-08-30T20:44:52+00:00"},{"url":"https://beincrypto.com/paid-network-rewards-community-for-support-during-hack/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20250913203711/https://beincrypto.com/paid-network-rewards-community-for-support-during-hack/","credibility":3,"archive_timestamp":"2025-09-13T20:37:11+00:00"},{"url":"https://theorg.com/org/paid-network/org-chart/kyle-chasse","name":"theorg.com","type":"other","archive_url":"https://web.archive.org/web/20260830131128/https://theorg.com/org/paid-network?p=kyle-chasse","credibility":3,"archive_timestamp":"2026-08-30T13:11:28+00:00"},{"url":"https://medium.com/theamaroom/paid-network-with-kyle-chasse-ama-t-me-amaroom-8f28aa4045bf","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coingecko.com/en/coins/paid-network","name":"coingecko.com","type":"other","archive_url":"http://web.archive.org/web/20250613193742/https://www.coingecko.com/en/coins/paid-network","credibility":3,"archive_timestamp":"2025-06-13T19:37:42+00:00"},{"url":"https://coinmarketcap.com/currencies/paid-network/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260518041726/https://coinmarketcap.com/currencies/paid-network/","credibility":3,"archive_timestamp":"2026-05-18T04:17:26+00:00"},{"url":"https://chainbroker.io/projects/paid-network/","name":"chainbroker.io","type":"other","archive_url":"https://web.archive.org/web/20260901071902/https://chainbroker.io/projects/paid-network/","credibility":3,"archive_timestamp":"2026-09-01T07:19:02+00:00"},{"url":"https://www.sec.gov/newsroom/press-releases/2024-95","name":"sec.gov","type":"other","archive_url":"http://web.archive.org/web/20260515180305/https://www.sec.gov/newsroom/press-releases/2024-95","credibility":3,"archive_timestamp":"2026-05-15T18:03:05+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:58.698232+00:00","updated_at":"2026-09-01T07:26:09.011489+00:00"}}