Payy pauses all transactions after $1.92 million USDC drained from its Ethereum bridge
Payy stops its network after a bridge exploit
Payy, a payments network focused on privacy and stablecoins, stopped all transactions on Sept. 24 after its Ethereum bridge was exploited. A bridge is a tool that moves assets between two blockchains, in this case between Ethereum and Payy's own network. A stablecoin is a crypto token designed to hold a steady value, usually close to one US dollar.
Onchain records show two withdrawal batches sent about 1.92 million USDC, a dollar-pegged stablecoin, to the same address linked to the attacker.
The two withdrawals and where the funds went
- The first batch ran at 12:21 a.m. ET and sent 1,828,589.38 USDC from the rollup contract at
0x367C1...85270to0xAa4985...B57E70. - The second batch ran at 5:30 a.m. ET and sent another 90,202.82 USDC to the same recipient.
- The Defiant's tally of the two payments comes to 1,918,792.20 USDC. The count leaves out withdrawals paid to other addresses in the same batches.
- The first amount was moved to a second wallet,
0xb483B...F3D38, and swapped through UniswapX into about 683 ETH. - Most of that ETH was then sent to three addresses: about 282.38 ETH to
0xe8d566...431956, and about 200 ETH each to0x888A21...132a2aand0x3d0927...F40104. - Both withdrawal batches called the bridge's
verifyRollupfunction.
What Payy told users
Payy confirmed the attack and said all Payy Network transactions were paused, including deposits, withdrawals, transfers and card transactions. It later confirmed that Payy Wallet functions were paused as well.
The company said it had notified law enforcement, exchanges and blockchain analytics companies about the attacker addresses. In its latest wallet update, Payy said it would give users next steps 'as soon as possible,' but it did not give a date for restarting the network.
Payy's public updates did not say what the vulnerability was, and they did not set out a plan to reimburse users.
Security firm points to a forged withdrawal
Security firm ExVul said its early analysis found a forged withdrawal hidden among ordinary user withdrawals in the first batch.
What is confirmed
- Payy confirmed the exploit and paused network and wallet activity.
- Onchain records show two withdrawal batches sending about 1.92 million USDC to one attacker-linked address.
- Part of the funds was converted into about 683 ETH and spread across three addresses.
- Payy says it contacted law enforcement, exchanges and analytics firms.
What is still unclear
- Payy has not publicly identified the vulnerability behind the withdrawals.
- There is no announced reimbursement plan for affected users.
- No restart date for the network or the wallet has been given.
Why the pause matters for Payy users
Until Payy restarts, users cannot make deposits, withdrawals or transfers, and card payments through the network do not work. The funds taken were converted into ETH and moved to several wallets, and Payy has not said whether users will be repaid.