Payy's Ethereum rollup bridge contract exploited for $1.83M USDC via forged withdrawal in verifyRollup batch.
Security & Exploits ·
Payy's bridge contract on Ethereum fell victim to an exploit at 4:21 UTC that resulted in the drainage of its complete holdings, totaling approximately $1.83 million in USDC. The attack involved a forged withdrawal embedded within a verifyRollup batch, allowing the attacker to circumvent standard verification mechanisms. Payy confirmed the incident and initiated an investigation while freezing all network operations—deposits, withdrawals, transfers, and card transactions among them.
The platform has engaged multiple incident response organizations and notified law enforcement as part of its formal security protocol. Payy characterizes the broader environment as facing what it terms a systemic security challenge. The specific vector exploited—a malformed entry within the batch verification process—points to a flaw in the rollup's validation layer that permitted unauthorized fund extraction without triggering detection systems designed to prevent such withdrawals.
What remains unclear is the complete attack timeline, whether the vulnerability existed since deployment, and whether any user funds held outside the bridge contract remain at risk. Details on the technical remediation planned and the timeline for resuming operations have not yet been disclosed.