Payy Network Halts Operations After $1.92M USDC Exploit
$1.92 million in USDC drained from Payy Network's Ethereum rollup. The attacker converted stolen stablecoins into roughly 683 ETH and distributed proceeds across three wallets before Payy halted all operations.
Payy Network Halts Operations After $1.92M USDC Exploit
$1.92 million in USDC drained from Payy Network's Ethereum rollup. The attacker converted the stolen stablecoins into roughly 683 ETH and distributed the proceeds across three separate wallets before Payy pulled the emergency brake on its entire platform.
Payy has suspended deposits, withdrawals, and card payments as of this week. The protocol has not published a post-mortem or disclosed the specific vulnerability exploited, leaving users and observers with limited visibility into how the breach occurred or whether funds are recoverable. The conversion from USDC to ETH and the immediate dispersal across multiple wallets follows a well-worn playbook: swap out of a freezable asset before Circle can blacklist the address, then fragment the trail.
That detail matters. USDC is a regulated stablecoin that Circle can freeze at the contract level. Once an attacker converts to ETH, that lever disappears. The speed of the conversion suggests the exploiter understood this window and moved deliberately. Circle's Arc mainnet uses USDC as native gas and targets institutional validators, illustrating how deeply stablecoin infrastructure is now embedded in on-chain architecture. That integration brings efficiency; it also means a single exploit can drain a protocol's entire liquid reserve in one transaction if the access controls fail.
"The initial proceeds were converted into about 683 ETH, with most then sent to three wallets. Payy has paused deposits, withdrawals and card payments."
Payy's decision to halt operations quickly may have capped the damage. A slower response could have allowed additional withdrawals or secondary exploits on a system already under stress. That said, a full operational shutdown is a blunt instrument, and users with funds on the platform now face an indefinite wait for any resolution. No timeline for resuming services has been announced.
The incident lands in a crowded field. Ethereum rollups and DeFi protocols have absorbed hundreds of millions in exploit losses over the past three years, and the attack pattern here, draining a rollup-based protocol, swapping to ETH, splitting across wallets, is nearly identical to incidents that hit smaller L2-adjacent platforms throughout 2024 and 2025. The frequency has not slowed adoption meaningfully, but it has intensified regulatory scrutiny of DeFi infrastructure. Proposals like those from a16z and the DeFi Education Fund asking the SEC to exempt decentralized exchanges from exchange registration become harder to advance when high-profile exploits keep refreshing the argument that DeFi platforms carry unmanaged risk.
The $1.92 million figure places this in the mid-tier of DeFi exploits by dollar value, but the operational impact is total: Payy is effectively offline. For users, that distinction is academic. Whether the vulnerability originated in Payy's specific smart contract implementation, its bridge architecture, or an operational security failure remains unknown. Until a full disclosure arrives, the honest answer is that the attack surface for this exploit has not been mapped publicly.
On-chain investigators and security firms will likely trace the ETH movements through the three recipient wallets in the coming days. If the attacker routes funds through a mixer like Tornado Cash or bridges to another chain, recovery becomes statistically unlikely. The next 48 to 72 hours are the critical window.






