Two transactions, five hours apart, both sent to the same address. That’s all it took to empty Payy’s Ethereum bridge of about $1.92 million in USDC. The company said it wasn’t a stolen key.
Payy runs a network for private stablecoin payments. On Friday it said on X that its initial root cause analysis found the drain “was NOT a compromised key, social engineering or exploit of our off-chain infrastructure.” It hasn’t published those findings. Payy said it’s checking them with an audit firm first.
That leaves an awkward gap. The company has ruled out the three most common explanations for a bridge drain, but it hasn’t said what did happen.
The money belonged to users
This wasn’t a treasury loss. Payy has confirmed the stolen funds were “users’ non-custodial deposits to Payy Network / Payy Wallet.” Both the network and Payy Wallet are now paused.
Payy first said that at 4:21 UTC on Sept. 24 its bridge contract “was exploited and drained of its full balance.” Deposits, withdrawals, transfers and card transactions went on hold. The bridge is a rollup contract that settles the network’s activity on Ethereum, which makes it the place where every user’s money ends up.
What the chain shows
We went through the Ethereum records, and they tell a tidier story than the company’s posts do. The first batch sent 1,828,589 USDC to one address at 4:21 UTC. It left about $95,000 in the bridge.
At 9:30 UTC, about five hours later, a second batch paid another 90,202 USDC to the same address. It left about $700 behind.
Both payouts went through verifyRollup, the function Payy uses to post batches of network activity to its bridge. Both came from the address that posts those batches. And that address wasn’t doing anything unusual. Every one of the last 200 transactions it sent, going back to late August, was a verifyRollup call to the bridge.
So the drain ran through Payy’s own settlement path, submitted by Payy’s own batch-posting address. Payy said that address’s key wasn’t compromised. On the record so far, it’s hard to see how else that happened.
A small test run, then the big one
The receiving address wasn’t new to Payy. It deposited 5 USDC on Sept. 22, withdrew 5 USDC later that day and deposited another 5 USDC on Sept. 23.
After the first payout, the money moved fast. Within about eight minutes it went to a second address and was sold through UniswapX for roughly 683 ETH. By 5:39 UTC, nearly all of that ether sat in three wallets.
The second payout was different. The 90,202 USDC was still sitting in the receiving address as of Friday afternoon.
What Payy hasn’t said
Payy said it had flagged the attacker’s addresses to law enforcement, exchanges and blockchain analytics firms. It paused Payy Wallet and promised details on next steps for users. It said it aims to share a validated report “in the next few days.”
Its posts leave out the parts depositors care about most. Payy hasn’t given a loss figure, hasn’t said whether users will be repaid and hasn’t said when the network will restart.
The drain also landed on a busy day. The same day, Bitget said about $351.6 million was taken from its hot and warm wallets in a separate incident.
If you have funds on Payy, there’s nothing you can do right now. Deposits, withdrawals and transfers are all frozen. What to watch for is whether the audited report explains how verifyRollup paid out money nobody authorized. And watch what happens to the 90,202 USDC that hadn’t moved as of Friday afternoon.
