Payy's post-mortem reveals $1.83M USDC exploit caused by an invalid burn proof accepted by its Noir/Barretenberg verifier.
Security & Exploits ·
Payy experienced a $1.83M USDC exploit stemming from a vulnerability in its proof verification system. An invalid burn proof was accepted by the protocol's Noir/Barretenberg verifier, allowing the unauthorized removal of funds. The incident prompted Payy to publish a post-mortem analysis detailing the technical failure.
The exploit centers on how Payy validates burn transactions—a core mechanism where tokens are permanently removed from circulation. In typical implementations, burns rely on cryptographic proofs to confirm that the operation occurred correctly before tokens are destroyed from supply. Payy's verifier failed to properly validate one such proof, creating a window for an attacker to drain USDC without actually executing a legitimate burn.
The exact scope of the vulnerability—whether it affected only a single proof submission or represented a broader flaw in the verification logic—remains unclear from available disclosures. The nature of the fix and whether similar proofs might have been accepted prior to discovery have not been detailed.