VYPR
breachPublished Sep 25, 2026· 1 source

Payy Network Suffers Major Breach as Ethereum Bridge Contract Drained

Attackers exploited Payy Network's Ethereum bridge contract, draining its full balance and forcing the platform to suspend all network and wallet functions.

Payy Network has confirmed a significant security incident where attackers successfully exploited its Ethereum bridge contract, draining the entire balance held within it. The breach, which occurred around 4:21 UTC on September 24, 2026, has led Payy to immediately suspend all network and wallet functions, including deposits, withdrawals, and transfers.

The compromised bridge contract was responsible for facilitating asset transfers between the Ethereum blockchain and the Payy Network. Cross-chain bridges are frequently targeted by threat actors due to the substantial pooled funds they often manage to enable inter-blockchain asset movement. In this instance, the attacker leveraged a vulnerability in the Ethereum-side contract to abscond with all available funds.

Payy clarified that the stolen assets represented users' non-custodial deposits that were connected to the Payy Network and Payy Wallet. This means the funds were not held in a traditional custodial account controlled by the company but were deposited by users through the bridge mechanism to access services within the Payy ecosystem. The exploit directly impacted these user-deposited funds.

Following the incident, Payy initiated a comprehensive shutdown of its services. All major transaction activities, including deposits, withdrawals, transfers, and even card transactions, have been temporarily halted. The Payy Wallet functionality has also been paused while the company's security teams conduct a thorough investigation into the attack and formulate a response plan for affected users.

Details regarding the specific vulnerability exploited, the total amount stolen, and the attacker's wallet addresses remain undisclosed by Payy. The company has not yet specified whether the exploit stemmed from a smart-contract logic flaw, an authorization bypass, a compromised privileged key, or another type of security weakness. However, Payy has confirmed that it has alerted law enforcement agencies, cryptocurrency exchanges, blockchain analytics firms, and other relevant organizations, providing them with attacker wallet addresses to aid in tracing the stolen assets and preventing their movement through centralized exchanges.

This incident underscores the persistent security risks associated with cross-chain bridge infrastructure. These contracts are inherently complex, managing large cryptocurrency reserves and relying on intricate validation, message-passing, minting, and withdrawal processes. A single flaw can provide an attacker with the means to forge withdrawals, circumvent verification mechanisms, replay transactions, or drain more assets than legitimately deposited.

For Payy users, the immediate advice is to refrain from interacting with any paused bridge, wallet, or network services until official recovery guidance is issued by the company. Users are also cautioned to be vigilant against potential phishing campaigns, impersonation attempts, and malicious links that may arise during the investigation period. Payy has stated it will provide further updates on its investigation, including technical details of the attack, the value of stolen assets, and plans for user reimbursement or fund recovery.

Synthesized by Vypr AI
Payy Network Suffers Major Breach as Ethereum Bridge Contract Drained · VYPR