Skip to main content
AVOID.NET

Payy Network

avoid.net/payy-network→18/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2rYdWu…NCgh

Summary

Payy Network is a zk-rollup stablecoin payments and crypto card platform built on Ethereum. On September 24, 2026, its Ethereum L1 rollup bridge contract was fully drained of approximately 1,832,149 USDC (~$1.83M) in a single transaction, prompting the platform to freeze all network, wallet, and card functions. The root cause has not been publicly confirmed by Payy; security firm ExVul alleged the attack batch was submitted using Payy's own prover and validator keys, suggesting a privileged key compromise rather than a public smart-contract bug.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Payy Network?

Timeline(6 events)

1 June 2026

Payy Network disclosed a critical vulnerability in its zk-circuit logic allowing potential forged burn messages. The flaw was reportedly patched in version 1.3.0 before exploitation.

Crypto Briefing

24 September 2026

At 04:21 UTC, an attacker called the verifyRollup function on Payy's Ethereum bridge contract at block 26044909, transferring approximately 1,832,149 USDC (~$1.83M) out of the contract in a single transaction.

CryptoTimes / CryptoSlate

24 September 2026

Stolen USDC was reportedly routed through the Railgun privacy protocol and converted to approximately 683 ETH, then distributed across multiple addresses, per Specter Investigation.

Kobaran (citing Specter Investigation)

24 September 2026

Payy Network suspended all deposits, withdrawals, transfers, and card payments platform-wide and initiated incident response protocols.

CryptoSlate

24 September 2026

Payy Network confirmed the exploit publicly at approximately 14:04 UTC, stating: 'Today at 4:21 UTC Payy's bridge contract on Ethereum was exploited and drained of its full balance.' The company announced it had notified law enforcement, exchanges, and blockchain analytics firms.

CryptoTimes

24 September 2026

Security firm ExVul alleged the attacker submitted the malicious batch using Payy's own prover key and that it was signed by Payy's own validator key, suggesting a privileged credential compromise.

Kobaran (citing ExVul)
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 1 of 8 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/25/2026, 5:06:29 PM

last updated: 9/25/2026, 7:14:38 PM

avoid.net — verified advice for a post-truth world