Payy Network Shutdown Follows $1.92M USDC Rollup Exploit
Payy Network has halted its payments platform after an attacker exploited a vulnerability in the project's Ethereum rollup contract, draining roughly $1.92 million in USDC.
The attack occurred on September 24, when a single malicious transaction passed through the contract's verifyRollup function, allowing the attacker to extract USDC that should have remained locked in the contract.
Specter Investigation traced the stolen funds through the Railgun privacy protocol, but it is unclear whether any of the funds can be recovered. The company has not indicated whether affected users will be made whole from its reserves.