Payy Network halts operations after $1.92M USDC exploit drains Ethereum rollup

1 hour ago 2



Payy Network shut down its entire payments platform on September 24 after an attacker exploited a vulnerability in its Ethereum rollup contract and walked away with roughly $1.83 million in USDC. Deposits, withdrawals, transfers, and card transactions all went dark as the team scrambled to contain the damage. The exploit hit at 04:21 UTC, buried inside a malicious verifyRollup transaction confirmed at block 26044909. What the attacker actually did Payy is built around a privacy-first stablecoin payments model, running on an Ethereum-based rollup. The rollup contract is effectively the bridge between what happens on Payy’s network and what gets settled on Ethereum mainnet, and that bridge is where the attacker found their opening. By crafting a transaction that passed through the verifyRollup function, the exploiter was able to extract USDC that should have remained locked in the contract. Blockchain investigation firm Specter Investigation traced the stolen funds through the Railgun privacy protocol, where the USDC was converted into approximately 683 ETH and then fanned out across multiple addresses. Payy confirmed the attack publicly and said all network operations were suspended...

Read Entire Article