Skip to main content
AVOID.NET

Payy Network — Noir/Barretenberg Verifier Flaw Post-Mortem

avoid.net/payy-network-noir-barretenberg-verifier-flaw-post-mortem→20/100·62% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3CJ5Zj…58Cq
last updated 2026-10-02

Summary

On September 24, 2026, Payy Network's Ethereum rollup bridge contract was drained of approximately $1.83–1.92 million in USDC across two transactions exploiting a zero-knowledge proof verification flaw. Payy's post-mortem attributed the root cause to a proving-system vulnerability in the Noir/Barretenberg verifier, a shared cryptographic library developed by Aztec rather than by Payy itself, while a related GitHub security advisory also describes a soundness flaw in Payy's own agg_agg aggregation circuit that failed to constrain unused message-array slots. This entry covers the incident and post-mortem only; see the related Payy Network page for the platform's overall trust assessment.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Payy Network — Noir/Barretenberg Verifier Flaw Post-Mortem?

Timeline(7 events)

14 May 2026

Aztec reportedly fixed a missing boundary-opening check (A(1) = 0) in Barretenberg's small-subgroup IPA verifier, per Payy's post-mortem as summarized by a secondary source.

SpendNode summary of Payy post-mortem

July 2026

The Barretenberg fix was shipped in release v5.0.0; Payy's deployment, pinned to an older version, reportedly did not receive the patch and was not notified.

SpendNode summary of Payy post-mortem

September 2026

An attacker exploited Payy's rollup bridge contract via the verifyRollup function, draining approximately 1,828,589 USDC in a first transaction, confirmed in Ethereum block 26044909; Payy paused all network and wallet operations.

Payy official statement on X, via Unchained and CryptoSlate

September 2026

A second transaction several hours after the first drained a further approximately 90,202 USDC to the same receiving address, bringing the combined total to roughly $1.92 million.

Unchained

September 2026

Payy stated it had completed initial root-cause analysis, ruled out a compromised key, social engineering, and off-chain infrastructure breach, and engaged a third-party audit firm to validate findings before publishing a full report.

SpendNode

September 2026

A GitHub security advisory and CVE (CVE-2026-48100) describing a soundness flaw in Payy's agg_agg aggregation circuit, patched in version 1.3.0, was published.

GitHub Security Advisory GHSA-fhxc-63vg-9gwr

September 2026

Payy published a technical post-mortem attributing the exploit's root cause to a proving-system vulnerability in the Noir/Barretenberg verifier developed by Aztec.

SpendNode summary of Payy post-mortem
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 8 of 12 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 10/2/2026, 5:14:58 PM

last updated: 10/2/2026, 6:10:04 PM

avoid.net — verified advice for a post-truth world