Payy Network — Noir/Barretenberg Verifier Flaw Post-Mortem
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3CJ5Zj…58CqSummary
On September 24, 2026, Payy Network's Ethereum rollup bridge contract was drained of approximately $1.83–1.92 million in USDC across two transactions exploiting a zero-knowledge proof verification flaw. Payy's post-mortem attributed the root cause to a proving-system vulnerability in the Noir/Barretenberg verifier, a shared cryptographic library developed by Aztec rather than by Payy itself, while a related GitHub security advisory also describes a soundness flaw in Payy's own agg_agg aggregation circuit that failed to constrain unused message-array slots. This entry covers the incident and post-mortem only; see the related Payy Network page for the platform's overall trust assessment.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(7 events)
14 May 2026
Aztec reportedly fixed a missing boundary-opening check (A(1) = 0) in Barretenberg's small-subgroup IPA verifier, per Payy's post-mortem as summarized by a secondary source.
SpendNode summary of Payy post-mortemJuly 2026
The Barretenberg fix was shipped in release v5.0.0; Payy's deployment, pinned to an older version, reportedly did not receive the patch and was not notified.
SpendNode summary of Payy post-mortemSeptember 2026
An attacker exploited Payy's rollup bridge contract via the verifyRollup function, draining approximately 1,828,589 USDC in a first transaction, confirmed in Ethereum block 26044909; Payy paused all network and wallet operations.
Payy official statement on X, via Unchained and CryptoSlateSeptember 2026
A second transaction several hours after the first drained a further approximately 90,202 USDC to the same receiving address, bringing the combined total to roughly $1.92 million.
UnchainedSeptember 2026
Payy stated it had completed initial root-cause analysis, ruled out a compromised key, social engineering, and off-chain infrastructure breach, and engaged a third-party audit firm to validate findings before publishing a full report.
SpendNodeSeptember 2026
A GitHub security advisory and CVE (CVE-2026-48100) describing a soundness flaw in Payy's agg_agg aggregation circuit, patched in version 1.3.0, was published.
GitHub Security Advisory GHSA-fhxc-63vg-9gwrSeptember 2026
Payy published a technical post-mortem attributing the exploit's root cause to a proving-system vulnerability in the Noir/Barretenberg verifier developed by Aztec.
SpendNode summary of Payy post-mortemDecision Log
- hash: Bho8HhVxdA3JpkkvB738sbLV3e98iuKtC4taEsbGAHi3
This investigation is cryptographically anchored to the Solana blockchain (1 event). 8 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 10/2/2026, 5:14:58 PM
last updated: 10/2/2026, 6:10:04 PM
avoid.net — verified advice for a post-truth world