Payy Network Suspended Operations After $1.83M Exploit
The platform halted all transactions following an exploit that drained USDC via a malicious rollup transaction.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust decentralized finance platforms to protect your digital assets from security breaches?
Payy Network suspended all deposits, withdrawals, and card services on September 24, 2026, after an attacker drained $1.83 million in USDC. The exploit was executed through a malicious transaction on the Ethereum network.
Why it matters
This incident highlights the persistent risks associated with bridge and rollup smart contracts, which remain primary targets for sophisticated exploits. The suspension leaves the future of user funds and platform services uncertain.
The attacker targeted the contract at Ethereum block 26044909, extracting $1.83 million in USDC. The stolen assets were subsequently converted into 683 ETH via the Railgun privacy protocol.
The players
Payy Network
A financial platform providing blockchain-based transactions and card services.
Railgun
A privacy protocol that provides anonymity for blockchain transactions through zero-knowledge proofs.
The details
The exploit leveraged a malicious verifyRollup transaction, a process used to validate batches of transactions on a secondary layer before submitting them to the main blockchain. By submitting this crafted data, the attacker bypassed the contract controls to extract the locked USDC. The stolen funds were then moved through the Railgun privacy protocol, a system that uses zero-knowledge proofs to obscure the origin and destination of transactions.
Timeline
June 2026: Payy Network disclosed and patched a critical vulnerability in its zk-circuit logic.
September 24, 2026, 04:21 UTC: The malicious transaction occurred at block 26044909.
September 24, 2026: Payy Network suspended all platform operations.
The Tech Race
This event highlights the risks inherent in the ongoing research into zk-circuit security, illustrating the difficulty of securing complex rollup contracts. It follows a pattern where platforms patching known vulnerabilities in zk-circuit logic remain susceptible to other architectural attack vectors.
All platform functionality, including deposits, withdrawals, and card transactions, remains suspended indefinitely for all users. There is no currently announced timeline for service restoration or information regarding the status of user balances.
The takeaway
Smart contract security requires constant vigilance, even after significant prior vulnerabilities are patched. Users should monitor official communications for any announcements regarding the potential recovery of assets or future platform status.
Further reading
For broader context on digital asset security trends, visit Cybersecurity.
Source note: This article includes information reported by Crypto Briefing.
Live Poll
Do you trust decentralized finance platforms to protect your digital assets from security breaches?






