Payy Network
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2rYdWu…NCghSummary
Payy Network is a zk-rollup stablecoin payments and crypto card platform built on Ethereum. On September 24, 2026, its Ethereum L1 rollup bridge contract was fully drained of approximately 1,832,149 USDC (~$1.83M) in a single transaction, prompting the platform to freeze all network, wallet, and card functions. The root cause has not been publicly confirmed by Payy; security firm ExVul alleged the attack batch was submitted using Payy's own prover and validator keys, suggesting a privileged key compromise rather than a public smart-contract bug.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(6 events)
1 June 2026
Payy Network disclosed a critical vulnerability in its zk-circuit logic allowing potential forged burn messages. The flaw was reportedly patched in version 1.3.0 before exploitation.
Crypto Briefing24 September 2026
At 04:21 UTC, an attacker called the verifyRollup function on Payy's Ethereum bridge contract at block 26044909, transferring approximately 1,832,149 USDC (~$1.83M) out of the contract in a single transaction.
CryptoTimes / CryptoSlate24 September 2026
Stolen USDC was reportedly routed through the Railgun privacy protocol and converted to approximately 683 ETH, then distributed across multiple addresses, per Specter Investigation.
Kobaran (citing Specter Investigation)24 September 2026
Payy Network suspended all deposits, withdrawals, transfers, and card payments platform-wide and initiated incident response protocols.
CryptoSlate24 September 2026
Payy Network confirmed the exploit publicly at approximately 14:04 UTC, stating: 'Today at 4:21 UTC Payy's bridge contract on Ethereum was exploited and drained of its full balance.' The company announced it had notified law enforcement, exchanges, and blockchain analytics firms.
CryptoTimes24 September 2026
Security firm ExVul alleged the attacker submitted the malicious batch using Payy's own prover key and that it was signed by Payy's own validator key, suggesting a privileged credential compromise.
Kobaran (citing ExVul)Decision Log
- hash: 94yCTug5onr72G7Sp8AYE6XTqpEDjdNJDpD2gwsCxAcv
This investigation is cryptographically anchored to the Solana blockchain (1 event). 1 of 8 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/25/2026, 5:06:29 PM
last updated: 9/25/2026, 7:14:38 PM
avoid.net — verified advice for a post-truth world