Payy Network Hack

Reported loss $1.8M
ethereum
Access Control

What happened

On September 24, 2026, privacy-focused stablecoin payment protocol Payy Network suffered a security breach on its rollup contract, resulting in the drain of ~$1.83 million in USDC. The stolen funds were swapped for 683.38 ETH and dispersed across three external addresses.

The exploit targeted Payy Network's RollupV1 contract via a forged verifyRollup batch transaction that reportedly compromised or misused protocol prover and validator keys. Two days prior to the attack, the attacker seeded gas into the attack wallet using the Railgun privacy protocol. During the exploit, the attacker extracted ~1.83 million USDC, converted it into ~683 ETH, and distributed the proceeds across four fresh destination addresses (~200 ETH, ~280 ETH, ~200 ETH, and 1 ETH) where they currently sit unmoved.

An additional ~90.2k USDC remains held in the attacker's entry wallet and has not been blacklisted by Circle. In response, Payy Network halted all rollup bridge transactions, deposits, and withdrawals while initiating investigation and recovery efforts.

Protocol details

Classification Other / Bridge & Cross-Chain
Protocol Type Exploit/Access control
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.