Payy Network Hack
What happened
On September 24, 2026, privacy-focused stablecoin payment protocol Payy Network suffered a security breach on its rollup contract, resulting in the drain of ~$1.83 million in USDC. The stolen funds were swapped for 683.38 ETH and dispersed across three external addresses.
The exploit targeted Payy Network's RollupV1 contract via a forged verifyRollup batch transaction that reportedly compromised or misused protocol prover and validator keys. Two days prior to the attack, the attacker seeded gas into the attack wallet using the Railgun privacy protocol. During the exploit, the attacker extracted ~1.83 million USDC, converted it into ~683 ETH, and distributed the proceeds across four fresh destination addresses (~200 ETH, ~280 ETH, ~200 ETH, and 1 ETH) where they currently sit unmoved.
An additional ~90.2k USDC remains held in the attacker's entry wallet and has not been blacklisted by Circle. In response, Payy Network halted all rollup bridge transactions, deposits, and withdrawals while initiating investigation and recovery efforts.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.