Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
450417284
Off-chain at
2026-09-25T17:16:45.181Z
Anchored at
—
Block time
—

Independent verification

1. Database (off-chain)
94yCTug5onr72G7Sp8AYE6XTqpEDjdNJDpD2gwsCxAcv
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (13323 chars)
{"actor":"system:backfill","investigation_id":"acfcb1c5-d03f-4e67-ae2f-60e8a37a8d1c","kind":"publish","page_slug":"payy-network","published_at":"2026-09-25T17:16:45.099Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Payy Network","sections":[{"content":"At approximately 04:21 UTC on September 24, 2026, an attacker called the verifyRollup function on Payy Network's Ethereum rollup bridge contract and transferred the contract's entire USDC balance in a single transaction. On-chain data at Ethereum block 26044909 shows approximately 1,832,149.4681 USDC was removed, with the primary receiving address (0xAa4985dBDaBfACa344237D40F7E06C4a0BB57E70) receiving approximately 1,828,589.38 USDC. Three additional smaller recipient addresses received the remaining balance. The transaction hash is reported as 0xf43abdac5422087f645d77923eb1c825178bff3eb86d17d40fa18d89701e1814. Payy Network confirmed the incident via a public post at 14:04 UTC on September 24, 2026, stating: 'Today at 4:21 UTC Payy's bridge contract on Ethereum was exploited and drained of its full balance.' The company noted that its investigation was ongoing and that all network transactions had been paused.","heading":"Bridge Exploit — September 24, 2026","severity":"critical","sources":[{"credibility":2,"name":"Payy bridge exploit freezes crypto cards, and no balances remain safe — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/payy-bridge-exploit-freezes-crypto-cards-and-no-balances-remain-safe/"},{"credibility":2,"name":"$1.83M in USDC Left Payy's Ethereum Rollup, But the Network Has Not Confirmed a Hack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/24/1-83-million-in-usdc-leaves-payy-networks-ethereum-rollup-contract/"},{"credibility":2,"name":"Attackers Siphon About $1.83M in USDC From Payy Rollup Bridge, Freezing Cards and Wallets — Kobaran","type":"news_article","url":"https://www.kobaran.com/attackers-siphon-about-1-83m-in-usdc-from-payy-rollup-bridge-freezing-cards-and-wallets/"},{"credibility":2,"name":"Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/payy-ethereum-bridge-contract-drain/"}]},{"content":"Security firm ExVul alleged in its post-incident analysis that the attacker submitted the malicious withdrawal batch using Payy's own prover key and that it was signed by Payy's own validator key. If accurate, this would indicate a privileged key compromise rather than a publicly exploitable smart-contract bug. Payy has not confirmed or denied ExVul's assessment, has not identified the attacker, and has not publicly disclosed the root cause of the exploit. Whether the compromise stemmed from stolen credentials, an insider incident, a flawed key-management process, or another vector remains unconfirmed as of the time of writing. Security researchers independently noted that the batch structure matched Payy's internal signing workflow.","heading":"Alleged Key Compromise","severity":"critical","sources":[{"credibility":2,"name":"Attackers Siphon About $1.83M in USDC From Payy Rollup Bridge, Freezing Cards and Wallets — Kobaran (citing ExVul)","type":"news_article","url":"https://www.kobaran.com/attackers-siphon-about-1-83m-in-usdc-from-payy-rollup-bridge-freezing-cards-and-wallets/"},{"credibility":2,"name":"Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"}]},{"content":"According to blockchain investigation firm Specter Investigation, the stolen USDC was routed through the Railgun privacy protocol following the exploit. The funds were reportedly converted into approximately 683 ETH and distributed across multiple addresses, materially hampering on-chain traceability. Payy stated it shared attacker-linked addresses with law enforcement agencies, cryptocurrency exchanges, and blockchain analytics firms in an effort to prevent liquidation and further laundering of the stolen assets. No recovery of funds had been publicly confirmed as of the most recent reporting.","heading":"Fund Movement and Tracing","severity":"high","sources":[{"credibility":2,"name":"Attackers Siphon About $1.83M in USDC From Payy Rollup Bridge, Freezing Cards and Wallets — Kobaran","type":"news_article","url":"https://www.kobaran.com/attackers-siphon-about-1-83m-in-usdc-from-payy-rollup-bridge-freezing-cards-and-wallets/"},{"credibility":2,"name":"Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"}]},{"content":"Following the exploit, Payy Network suspended all platform functions, including deposits, withdrawals, transfers, and card payments. Users were unable to access balances or conduct transactions as of September 24, 2026. Payy has not disclosed the number of affected users, whether user funds held on the platform beyond the bridge contract balance are at risk, or what — if any — reimbursement or recovery plan exists. No restoration timeline has been published. The platform stated it was working with law enforcement and cybersecurity professionals but provided no further operational detail.","heading":"Platform Suspension and User Impact","severity":"critical","sources":[{"credibility":2,"name":"Payy bridge exploit freezes crypto cards, and no balances remain safe — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/payy-bridge-exploit-freezes-crypto-cards-and-no-balances-remain-safe/"},{"credibility":2,"name":"Payy Halts Network After $1.83M Ethereum Bridge Exploit Hits — Coin Edition","type":"news_article","url":"https://coinedition.com/crypto-live-news/payy-halts-network-after-1-83m-ethereum-bridge-exploit-hits/"},{"credibility":2,"name":"Payy Halts Network After $1.83M Ethereum Bridge Exploit Hits — Phemex News","type":"news_article","url":"https://phemex.com/news/article/payy-network-halts-all-transactions-after-ethereum-bridge-contract-drained-in-attack-97788"}]},{"content":"In June 2026, Payy Network disclosed a critical vulnerability in its zk-circuit logic — the cryptographic layer responsible for generating the zero-knowledge proofs underpinning the platform's privacy model. The flaw allegedly permitted the potential creation of forged burn messages, meaning an attacker could theoretically signal that tokens had been destroyed when they had not been. Payy reported that the flaw was patched in version 1.3.0 before any funds were lost. It is not publicly confirmed whether the June 2026 circuit vulnerability is related to the September 2026 bridge exploit. No independent audit confirming the patch's sufficiency has been publicly cited.","heading":"Prior Security Disclosure — June 2026 ZK-Circuit Flaw","severity":"medium","sources":[{"credibility":2,"name":"Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"}]},{"content":"As of September 24–25, 2026, Payy Network had not publicly disclosed: the attacker's identity or wallet addresses, a verified transaction hash for the exploit, the technical root cause of the bridge drain, the total scope of potential user losses beyond the bridge contract, a timeline for service restoration, or a compensation plan for affected users. The only official statement confirmed the exploit occurred and that all transactions were paused. This level of disclosure is materially below the standard set by comparable post-exploit responses in the industry. The absence of a post-mortem or preliminary root-cause statement within 24 hours of a full-bridge drain represents a significant transparency gap.","heading":"Transparency and Disclosure Gaps","severity":"high","sources":[{"credibility":2,"name":"$1.83M in USDC Left Payy's Ethereum Rollup, But the Network Has Not Confirmed a Hack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/24/1-83-million-in-usdc-leaves-payy-networks-ethereum-rollup-contract/"},{"credibility":2,"name":"Payy bridge exploit freezes crypto cards, and no balances remain safe — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/payy-bridge-exploit-freezes-crypto-cards-and-no-balances-remain-safe/"}]}],"sources_used":[{"credibility":2,"name":"Payy bridge exploit freezes crypto cards, and no balances remain safe — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/payy-bridge-exploit-freezes-crypto-cards-and-no-balances-remain-safe/"},{"credibility":2,"name":"Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/payy-ethereum-bridge-contract-drain/"},{"credibility":2,"name":"Payy Halts Network After $1.83M Ethereum Bridge Exploit Hits — Phemex News","type":"news_article","url":"https://phemex.com/news/article/payy-network-halts-all-transactions-after-ethereum-bridge-contract-drained-in-attack-97788"},{"credibility":2,"name":"Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"},{"credibility":2,"name":"$1.83M in USDC Left Payy's Ethereum Rollup, But the Network Has Not Confirmed a Hack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/24/1-83-million-in-usdc-leaves-payy-networks-ethereum-rollup-contract/"},{"credibility":2,"name":"Attackers Siphon About $1.83M in USDC From Payy Rollup Bridge, Freezing Cards and Wallets — Kobaran","type":"news_article","url":"https://www.kobaran.com/attackers-siphon-about-1-83m-in-usdc-from-payy-rollup-bridge-freezing-cards-and-wallets/"},{"credibility":2,"name":"Payy Halts Network After $1.83M Ethereum Bridge Exploit Hits — Coin Edition","type":"news_article","url":"https://coinedition.com/crypto-live-news/payy-halts-network-after-1-83m-ethereum-bridge-exploit-hits/"},{"credibility":2,"name":"Attackers Drain Payy Network After Exploiting Ethereum Bridge Contract — GBHackers","type":"news_article","url":"https://gbhackers.com/attackers-drain-payy-network/"}],"summary":"Payy Network is a zk-rollup stablecoin payments and crypto card platform built on Ethereum. On September 24, 2026, its Ethereum L1 rollup bridge contract was fully drained of approximately 1,832,149 USDC (~$1.83M) in a single transaction, prompting the platform to freeze all network, wallet, and card functions. The root cause has not been publicly confirmed by Payy; security firm ExVul alleged the attack batch was submitted using Payy's own prover and validator keys, suggesting a privileged key compromise rather than a public smart-contract bug.","timeline":[{"date":"2026-06-01","event":"Payy Network disclosed a critical vulnerability in its zk-circuit logic allowing potential forged burn messages. The flaw was reportedly patched in version 1.3.0 before exploitation.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"},{"date":"2026-09-24","event":"At 04:21 UTC, an attacker called the verifyRollup function on Payy's Ethereum bridge contract at block 26044909, transferring approximately 1,832,149 USDC (~$1.83M) out of the contract in a single transaction.","source":"CryptoTimes / CryptoSlate","source_url":"https://www.cryptotimes.io/2026/09/24/1-83-million-in-usdc-leaves-payy-networks-ethereum-rollup-contract/"},{"date":"2026-09-24","event":"Stolen USDC was reportedly routed through the Railgun privacy protocol and converted to approximately 683 ETH, then distributed across multiple addresses, per Specter Investigation.","source":"Kobaran (citing Specter Investigation)","source_url":"https://www.kobaran.com/attackers-siphon-about-1-83m-in-usdc-from-payy-rollup-bridge-freezing-cards-and-wallets/"},{"date":"2026-09-24","event":"Payy Network suspended all deposits, withdrawals, transfers, and card payments platform-wide and initiated incident response protocols.","source":"CryptoSlate","source_url":"https://cryptoslate.com/payy-bridge-exploit-freezes-crypto-cards-and-no-balances-remain-safe/"},{"date":"2026-09-24","event":"Payy Network confirmed the exploit publicly at approximately 14:04 UTC, stating: 'Today at 4:21 UTC Payy's bridge contract on Ethereum was exploited and drained of its full balance.' The company announced it had notified law enforcement, exchanges, and blockchain analytics firms.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/24/1-83-million-in-usdc-leaves-payy-networks-ethereum-rollup-contract/"},{"date":"2026-09-24","event":"Security firm ExVul alleged the attacker submitted the malicious batch using Payy's own prover key and that it was signed by Payy's own validator key, suggesting a privileged credential compromise.","source":"Kobaran (citing ExVul)","source_url":"https://www.kobaran.com/attackers-siphon-about-1-83m-in-usdc-from-payy-rollup-bridge-freezing-cards-and-wallets/"}]},"v":1}