Payy Network Suspended Operations After $1.83M Exploit

The platform halted all transactions following an exploit that drained USDC via a malicious rollup transaction.

Updated on Sept. 24, 2026 in Cybersecurity

Isometric editorial illustration showing a complex digital structure of cubes and prisms, representing cybersecurity architecture.
Payy Network suspended all platform operations on September 24 following a $1.83 million exploit of its rollup smart contract infrastructure. AI Illustration. Upload story photo >

Live Poll

Do you trust decentralized finance platforms to protect your digital assets from security breaches?

Payy Network suspended all deposits, withdrawals, and card services on September 24, 2026, after an attacker drained $1.83 million in USDC. The exploit was executed through a malicious transaction on the Ethereum network.

Why it matters

This incident highlights the persistent risks associated with bridge and rollup smart contracts, which remain primary targets for sophisticated exploits. The suspension leaves the future of user funds and platform services uncertain.

The attacker targeted the contract at Ethereum block 26044909, extracting $1.83 million in USDC. The stolen assets were subsequently converted into 683 ETH via the Railgun privacy protocol.

The players

Payy Network

A financial platform providing blockchain-based transactions and card services.

Railgun

A privacy protocol that provides anonymity for blockchain transactions through zero-knowledge proofs.

The details

The exploit leveraged a malicious verifyRollup transaction, a process used to validate batches of transactions on a secondary layer before submitting them to the main blockchain. By submitting this crafted data, the attacker bypassed the contract controls to extract the locked USDC. The stolen funds were then moved through the Railgun privacy protocol, a system that uses zero-knowledge proofs to obscure the origin and destination of transactions.

Timeline

  1. June 2026: Payy Network disclosed and patched a critical vulnerability in its zk-circuit logic.

  2. September 24, 2026, 04:21 UTC: The malicious transaction occurred at block 26044909.

  3. September 24, 2026: Payy Network suspended all platform operations.

The Tech Race

This event highlights the risks inherent in the ongoing research into zk-circuit security, illustrating the difficulty of securing complex rollup contracts. It follows a pattern where platforms patching known vulnerabilities in zk-circuit logic remain susceptible to other architectural attack vectors.

All platform functionality, including deposits, withdrawals, and card transactions, remains suspended indefinitely for all users. There is no currently announced timeline for service restoration or information regarding the status of user balances.

The takeaway

Smart contract security requires constant vigilance, even after significant prior vulnerabilities are patched. Users should monitor official communications for any announcements regarding the potential recovery of assets or future platform status.

Further reading

For broader context on digital asset security trends, visit Cybersecurity.

Source note: This article includes information reported by Crypto Briefing.

Live Poll

Do you trust decentralized finance platforms to protect your digital assets from security breaches?

Payy Network Suspended Operations After $1.83M Exploit