An attacker exploited Payy Network’s Ethereum bridge contract, draining approximately $1.92 million USDC from user non-custodial deposits tied to Payy Network and Payy Wallet. Blockchain analysis found that two withdrawal batches sent funds to an attacker-linked address; a forged withdrawal was reportedly mixed with legitimate withdrawals in the first batch, with both batches calling the bridge’s verifyRollup function. The attacker converted the larger tranche through UniswapX into about 683 ETH and dispersed it across three addresses.
Payy halted deposits, withdrawals, transfers, card transactions, and Payy Wallet operations after detecting the compromise. The company notified law enforcement, cryptocurrency exchanges, blockchain analytics providers, and other relevant parties, but has not publicly identified the underlying vulnerability, disclosed attacker wallet addresses, announced a recovery timeline, or committed to a reimbursement plan for affected users.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
After the Ethereum bridge contract was exploited and drained, Payy suspended deposits, withdrawals, transfers, card transactions, and Payy Wallet functionality. The incident affected users' non-custodial deposits associated with Payy Network and Payy Wallet.
A second attacker-linked withdrawal batch transferred 90,202.82 USDC to 0xAa4985...B57E70 at 5:30 a.m. ET. Both withdrawal batches invoked the Ethereum bridge's verifyRollup function.
At approximately 04:21 UTC (12:21 a.m. ET), a withdrawal batch transferred 1,828,589.38 USDC from Payy's rollup contract to attacker-linked address 0xAa4985...B57E70. ExVul later assessed that the batch included a forged withdrawal mixed with normal user withdrawals.
Payy notified law enforcement, cryptocurrency exchanges, and blockchain analytics organizations about the attacker addresses to support tracing and disrupt potential cash-out activity. The company said its investigation was ongoing.
The first stolen tranche was moved to wallet 0xb483B...F3D38, converted through UniswapX into roughly 683 ETH, and distributed across three addresses, including transfers of approximately 282.38 ETH, 200 ETH, and 200 ETH.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.