Payy Network Payments Freeze After $1.83M Ethereum Rollup Exploit
Payy Network's entire payments platform went dark on September 24 after an attacker exploited a vulnerability in its Ethereum rollup contract, making off with approximately $1.83 million in USDC.
The exploit occurred at 04:21 UTC and was hidden inside a malicious verifyRollup transaction confirmed at block 26044909.
Pretty's payment system is built around a privacy-first stablecoin model running on an Ethereum-based rollup, with the rollup contract serving as a bridge between what happens on Payy’s network and what gets settled on Ethereum mainnet.
The attacker was able to extract USDC from the contract by crafting a transaction that passed through the verifyRollup function.