Payy Network Suspended Operations After USDC Exploit

The platform halted all transactions following the theft of $1.83 million in USDC from its contract.

Updated on Sept. 24, 2026 in Cybersecurity

Isometric editorial illustration of a hexagonal crystalline structure with a single detached block, representing a digital security breach.
Payy Network suspended all services on September 24, 2026, after a smart contract exploit led to the theft of $1.83 million in USDC. AI Illustration. Upload story photo >

Live Poll

Do you trust decentralized finance platforms to protect your digital assets from security breaches?

Payy Network suspended all deposits, withdrawals, and card services on September 24, 2026, after an attacker drained $1.83 million in USDC. The exploit was executed via a malicious transaction on the Ethereum network.

Why it matters

The breach highlights ongoing security risks for decentralized finance platforms involving rollup bridges and smart contract logic. It remains unclear if the network will resume operations or if affected users will be compensated for their losses.

The attacker targeted a rollup bridge vulnerability by executing a malicious verifyRollup transaction at Ethereum block 26044909. The stolen assets were subsequently obfuscated through the Railgun privacy protocol and converted into 683 ETH.

The players

Payy Network

This is a decentralized finance platform that facilitates digital asset transactions and card payments.

Railgun

This is a privacy protocol used to obscure transaction trails on the blockchain.

The details

The attacker exploited the Payy Network contract to extract locked USDC assets, effectively bypassing security protocols. Although the company previously resolved a zk-circuit vulnerability in version 1.3.0 earlier this year, this latest breach successfully compromised the platform.

Timeline

  1. In June 2026, Payy Network disclosed and addressed a separate security flaw.

  2. The exploit occurred at 04:21 UTC on September 24, 2026.

  3. Payy Network suspended all platform operations on September 24, 2026.

The Tech Race

This incident underscores the persistent security challenges facing the Ethereum rollup bridge architecture, which remains a primary target for decentralized finance exploits. It illustrates a critical vulnerability in contract logic that developers must overcome to compete with legacy financial systems.

Users of the Payy Network currently have no access to their funds or the ability to perform any transactions. The indefinite suspension of services means that account holders cannot move or spend their assets until further notice from the platform administrators.

The takeaway

DeFi users should remain cautious of platforms with complex zk-circuit logic that have historical security disclosures. Always verify if a protocol has undergone recent audits and ensure your assets are not locked in contracts currently under suspension.

Further reading

For more information on digital asset security, visit the Cybersecurity section.

Live Poll

Do you trust decentralized finance platforms to protect your digital assets from security breaches?