Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
452674705
Off-chain at
2026-10-02T17:15:04.846Z
Anchored at
2026-10-02T17:15:35.313Z
Block time
—

Independent verification

1. Database (off-chain)
Bho8HhVxdA3JpkkvB738sbLV3e98iuKtC4taEsbGAHi3
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (17498 chars)
{"actor":"system:backfill","investigation_id":"4bac3cd6-8c34-406c-86f0-9ffb2e61b883","kind":"publish","page_slug":"payy-network-noir-barretenberg-verifier-flaw-post-mortem","published_at":"2026-10-02T17:15:04.675Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Payy Network — Noir/Barretenberg Verifier Flaw Post-Mortem","sections":[{"content":"At approximately 04:21 UTC on September 24, 2026, an attacker submitted a malicious transaction through Payy's verifyRollup function on Ethereum, the mechanism by which the rollup contract confirms off-chain transaction batches. The transaction was confirmed in Ethereum block 26044909. A first transfer moved 1,828,589.378132 USDC out of the rollup contract to a single receiving address. A second, smaller transaction roughly five hours later (reported as occurring around 09:30 UTC) released a further 90,202.820016 USDC to the same address, after an initial 1 USDC burn was paid by a third-party 'burn substitutor' and later reimbursed. Combined, reporting places the total drained between approximately $1.83 million and $1.92 million in USDC, with the discrepancy reflecting whether only the large first transfer or both transactions are counted. Payy paused all network operations, including deposits, withdrawals, transfers, and card transactions, shortly after the exploit was detected by outside observers and confirmed by the team on social media.","heading":"The Exploit","severity":"critical","sources":[{"credibility":2,"name":"Payy Halts Network After $1.83M Ethereum Bridge Exploit (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/09/24/1-83-million-in-usdc-leaves-payy-networks-ethereum-rollup-contract/"},{"credibility":2,"name":"Payy bridge exploit freezes crypto cards, and no balances remain safe (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/payy-bridge-exploit-freezes-crypto-cards-and-no-balances-remain-safe/"},{"credibility":2,"name":"Payy Rules Out a Compromised Key in $1.92 Million Drain of Users' Deposits (Unchained)","type":"news_article","url":"https://unchainedcrypto.com/payy-rules-out-a-compromised-key-in-1-92-million-drain-of-users-deposits"},{"credibility":2,"name":"Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup (CryptoBriefing)","type":"news_article","url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"}]},{"content":"Payy's official account posted that the bridge contract had been 'exploited and drained of its full balance' and that the team was 'following incident response guidelines.' The company subsequently stated the incident was 'NOT a compromised key, social engineering or exploit of our off-chain infrastructure,' pointing investigators toward an on-chain, cryptographic cause rather than operational security failure. Payy said it had notified law enforcement, exchanges, and blockchain analytics firms of the attacker's addresses, and reported commissioning an independent third-party audit firm to validate its internal root-cause analysis before publishing a full report. As of the most recent reporting reviewed, Payy had not announced a timeline for restoring service or confirmed whether affected users would be made whole.","heading":"Official Response and Denials","severity":"high","sources":[{"credibility":2,"name":"Payy Confirms Exploit, Rules Out Key and Social Engineering Attacks (SpendNode)","type":"news_article","url":"https://www.spendnode.io/blog/payy-confirms-exploit-third-party-audit-september-2026/"},{"credibility":2,"name":"Payy Rules Out a Compromised Key in $1.92 Million Drain of Users' Deposits (Unchained)","type":"news_article","url":"https://unchainedcrypto.com/payy-rules-out-a-compromised-key-in-1-92-million-drain-of-users-deposits"},{"credibility":3,"name":"Payy (@payy_link) statement on X regarding attacker addresses","type":"social_media","url":"https://x.com/payy_link/status/2103153035895877914"}]},{"content":"Payy's published post-mortem concluded that an attacker submitted an invalid burn proof that Payy's deployed Noir and Barretenberg verifier incorrectly accepted as valid, framing the root cause as a proving-system vulnerability in software developed by Aztec rather than by Payy. Secondary reporting citing the post-mortem states that Barretenberg's small-subgroup IPA verifier was missing a boundary-opening check (described as 'A(1) = 0'), that Aztec fixed this in a commit dated May 14, 2026 and shipped the fix in Barretenberg v5.0.0 on July 13, 2026, and that Payy's deployment remained pinned to an older version (bb 3.0.0-manual.20251030 / Noir 1.0.0-beta.14) that never received the patch and was not proactively notified of the fix by Aztec. This narrative places responsibility on an upstream dependency silently patched without downstream notification. These specific technical claims — the exact commit, version numbers, and notification failure — are sourced only to a single secondary blog (SpendNode) summarizing Payy's post-mortem; the underlying Payy post-mortem document and any Aztec statement confirming or disputing this account could not be independently located, so this section should be treated as lower-confidence pending a primary source.","heading":"Post-Mortem: Noir/Barretenberg Verifier Attribution","severity":"high","sources":[{"credibility":2,"name":"Payy Post-Mortem Blames Noir Verifier Flaw for $1.9M Bridge Loss (SpendNode)","type":"news_article","url":"https://www.spendnode.io/blog/payy-post-mortem-noir-verifier-flaw-1-9m-usdc-september-2026/"}]},{"content":"A GitHub Security Advisory for the polybase/payy repository (GHSA-fhxc-63vg-9gwr, assigned CVE-2026-48100) describes a distinct but related soundness flaw in Payy's own 'agg_agg' recursive-aggregation circuit, rather than in Aztec's shared verifier code. According to the advisory, prior to version 1.3.0 the agg_agg circuit forwarded the compacted message stream from inner proofs into a public messages array without constraining the unused tail of that array to zero. This allowed a registered prover to construct a valid aggregate proof for an approved rollup block while inserting an extra, forged burn message after the legitimate ones; Payy's RollupV1.verifyRollup() contract would then parse the forged entry as a normal burn instruction and transfer USDC to the attacker. The advisory credits a researcher identified as 'loopghost' and lists the affected circuit version as zk-circuits-v1.1.12, patched in payy v1.3.0. Vulnerability databases mirroring this advisory give inconsistent severity ratings (one lists it as 'Critical,' another as 'High' with a CVSS score of 8.7) and inconsistent publication dates, with at least one aggregator listing a June 2026 publication date that would predate the September 24, 2026 exploit. This date inconsistency could not be resolved from available sources and may reflect a GHSA 'introduced version' backdating convention rather than actual pre-exploit public disclosure; it should not be read as confirmed evidence the flaw was publicly known before the attack. It is unclear from available sources whether the agg_agg circuit flaw and the Noir/Barretenberg verifier flaw described in Payy's own post-mortem are the same vulnerability described two different ways, or two separate, overlapping weaknesses that both contributed to the incident.","heading":"Alternative/Overlapping Technical Account: agg_agg Circuit Flaw (CVE-2026-48100)","severity":"critical","sources":[{"credibility":1,"name":"GHSA-fhxc-63vg-9gwr: agg_agg trailing message slots are unconstrained and allow forged burn messages","type":"official","url":"https://github.com/polybase/payy/security/advisories/GHSA-fhxc-63vg-9gwr"},{"credibility":2,"name":"CVE-2026-48100 (Hol.org threat intelligence mirror)","type":"research","url":"https://hol.org/guard/security/cves/CVE-2026-48100-payy-aggagg-trailing-message-slots-are"},{"credibility":2,"name":"CVE-2026-48100: payy Vulnerability (CVSS 8.7) (Strix.ai)","type":"research","url":"https://www.strix.ai/cve/CVE-2026-48100"}]},{"content":"Multiple outlets reported that the stolen USDC was routed through the Railgun privacy protocol, converted into approximately 683 ETH, and then distributed across multiple downstream addresses, consistent with an attempt to obscure the funds' trail. Payy stated it had flagged the attacker's addresses to law enforcement, centralized exchanges, and blockchain analytics firms. No information reviewed indicates that any portion of the stolen funds had been recovered or frozen as of the most recent reporting.","heading":"Fund Movement and Laundering","severity":"high","sources":[{"credibility":2,"name":"Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network (Cyber Security News)","type":"news_article","url":"https://cybersecuritynews.com/payy-ethereum-bridge-contract-drain/"},{"credibility":2,"name":"Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup (CryptoBriefing)","type":"news_article","url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"}]},{"content":"At least one secondary source states that this was Payy's second significant security issue in 2026, asserting the company had patched a critical zero-knowledge circuit logic flaw in June 2026 before it was exploited. This claim comes from a single Tier 2/3 source and could not be independently corroborated against a primary disclosure or second outlet, so it is presented here as unverified and should be treated with low confidence.","heading":"Prior Security History","severity":"medium","sources":[{"credibility":2,"name":"Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup (CryptoBriefing)","type":"news_article","url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"}]},{"content":"The exploit froze all Payy Wallet and card functionality, leaving users unable to deposit, withdraw, transfer, or spend funds through the platform while the investigation proceeded. As of the most recent reporting reviewed, Payy had not disclosed how many users were affected, the total scope of customer losses, whether affected non-custodial deposits would be reimbursed, or a timeline for resuming service. Commentary accompanying the coverage warned users to watch for phishing campaigns and fake reimbursement or 'token recovery' links exploiting the incident, though no specific instances of such scams targeting Payy users were documented in the sources reviewed.","heading":"User Impact and Unresolved Questions","severity":"high","sources":[{"credibility":2,"name":"Payy bridge exploit freezes crypto cards, and no balances remain safe (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/payy-bridge-exploit-freezes-crypto-cards-and-no-balances-remain-safe/"},{"credibility":3,"name":"Attackers Siphon About $1.83M in USDC From Payy Rollup Bridge, Freezing Cards and Wallets (Kobaran)","type":"news_article","url":"https://www.kobaran.com/attackers-siphon-about-1-83m-in-usdc-from-payy-rollup-bridge-freezing-cards-and-wallets/"}]}],"sources_used":[{"credibility":2,"name":"Payy Post-Mortem Blames Noir Verifier Flaw for $1.9M Bridge Loss (SpendNode)","type":"news_article","url":"https://www.spendnode.io/blog/payy-post-mortem-noir-verifier-flaw-1-9m-usdc-september-2026/"},{"credibility":2,"name":"Payy Confirms Exploit, Rules Out Key and Social Engineering Attacks (SpendNode)","type":"news_article","url":"https://www.spendnode.io/blog/payy-confirms-exploit-third-party-audit-september-2026/"},{"credibility":2,"name":"Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup (CryptoBriefing)","type":"news_article","url":"https://cryptobriefing.com/payy-network-halt-usdc-exploit-ethereum-rollup/"},{"credibility":2,"name":"Payy Rules Out a Compromised Key in $1.92 Million Drain of Users' Deposits (Unchained)","type":"news_article","url":"https://unchainedcrypto.com/payy-rules-out-a-compromised-key-in-1-92-million-drain-of-users-deposits"},{"credibility":2,"name":"Payy bridge exploit freezes crypto cards, and no balances remain safe (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/payy-bridge-exploit-freezes-crypto-cards-and-no-balances-remain-safe/"},{"credibility":2,"name":"Payy Halts Network After $1.83M Ethereum Bridge Exploit (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/09/24/1-83-million-in-usdc-leaves-payy-networks-ethereum-rollup-contract/"},{"credibility":2,"name":"Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network (Cyber Security News)","type":"news_article","url":"https://cybersecuritynews.com/payy-ethereum-bridge-contract-drain/"},{"credibility":3,"name":"Attackers Siphon About $1.83M in USDC From Payy Rollup Bridge, Freezing Cards and Wallets (Kobaran)","type":"news_article","url":"https://www.kobaran.com/attackers-siphon-about-1-83m-in-usdc-from-payy-rollup-bridge-freezing-cards-and-wallets/"},{"credibility":1,"name":"GHSA-fhxc-63vg-9gwr: agg_agg trailing message slots are unconstrained and allow forged burn messages","type":"official","url":"https://github.com/polybase/payy/security/advisories/GHSA-fhxc-63vg-9gwr"},{"credibility":2,"name":"CVE-2026-48100 (Hol.org threat intelligence mirror)","type":"research","url":"https://hol.org/guard/security/cves/CVE-2026-48100-payy-aggagg-trailing-message-slots-are"},{"credibility":2,"name":"CVE-2026-48100: payy Vulnerability (CVSS 8.7) (Strix.ai)","type":"research","url":"https://www.strix.ai/cve/CVE-2026-48100"},{"credibility":3,"name":"Payy (@payy_link) statement on X regarding attacker addresses","type":"social_media","url":"https://x.com/payy_link/status/2103153035895877914"}],"summary":"On September 24, 2026, Payy Network's Ethereum rollup bridge contract was drained of approximately $1.83–1.92 million in USDC across two transactions exploiting a zero-knowledge proof verification flaw. Payy's post-mortem attributed the root cause to a proving-system vulnerability in the Noir/Barretenberg verifier, a shared cryptographic library developed by Aztec rather than by Payy itself, while a related GitHub security advisory also describes a soundness flaw in Payy's own agg_agg aggregation circuit that failed to constrain unused message-array slots. This entry covers the incident and post-mortem only; see the related Payy Network page for the platform's overall trust assessment.","timeline":[{"date":"2026-05-14","date_evidence":"Aztec fixed it in 58bf73a (14 May 2026)","event":"Aztec reportedly fixed a missing boundary-opening check (A(1) = 0) in Barretenberg's small-subgroup IPA verifier, per Payy's post-mortem as summarized by a secondary source.","source":"SpendNode summary of Payy post-mortem","source_url":"https://www.spendnode.io/blog/payy-post-mortem-noir-verifier-flaw-1-9m-usdc-september-2026/"},{"date":"2026-07","date_evidence":"shipped it in v5.0.0 (13 Jul)","date_original":"2026-07-13","event":"The Barretenberg fix was shipped in release v5.0.0; Payy's deployment, pinned to an older version, reportedly did not receive the patch and was not notified.","source":"SpendNode summary of Payy post-mortem","source_url":"https://www.spendnode.io/blog/payy-post-mortem-noir-verifier-flaw-1-9m-usdc-september-2026/"},{"date":"2026-09","date_evidence":"Today at 4:21 UTC Payy's bridge contract on Ethereum was exploited and drained of its full balance.","date_original":"2026-09-24","event":"An attacker exploited Payy's rollup bridge contract via the verifyRollup function, draining approximately 1,828,589 USDC in a first transaction, confirmed in Ethereum block 26044909; Payy paused all network and wallet operations.","source":"Payy official statement on X, via Unchained and CryptoSlate","source_url":"https://unchainedcrypto.com/payy-rules-out-a-compromised-key-in-1-92-million-drain-of-users-deposits"},{"date":"2026-09","date_original":"2026-09-24","event":"A second transaction several hours after the first drained a further approximately 90,202 USDC to the same receiving address, bringing the combined total to roughly $1.92 million.","source":"Unchained","source_url":"https://unchainedcrypto.com/payy-rules-out-a-compromised-key-in-1-92-million-drain-of-users-deposits"},{"date":"2026-09","date_original":"2026-09-25","event":"Payy stated it had completed initial root-cause analysis, ruled out a compromised key, social engineering, and off-chain infrastructure breach, and engaged a third-party audit firm to validate findings before publishing a full report.","source":"SpendNode","source_url":"https://www.spendnode.io/blog/payy-confirms-exploit-third-party-audit-september-2026/"},{"date":"2026-09","date_original":"2026-09-28","event":"A GitHub security advisory and CVE (CVE-2026-48100) describing a soundness flaw in Payy's agg_agg aggregation circuit, patched in version 1.3.0, was published.","source":"GitHub Security Advisory GHSA-fhxc-63vg-9gwr","source_url":"https://github.com/polybase/payy/security/advisories/GHSA-fhxc-63vg-9gwr"},{"date":"2026-09","date_original":"2026-09-29","event":"Payy published a technical post-mortem attributing the exploit's root cause to a proving-system vulnerability in the Noir/Barretenberg verifier developed by Aztec.","source":"SpendNode summary of Payy post-mortem","source_url":"https://www.spendnode.io/blog/payy-post-mortem-noir-verifier-flaw-1-9m-usdc-september-2026/"}]},"v":1}