Attackers Drain Payy Network After Exploiting Ethereum Bridge Contract
Attackers exploited Payy Network's Ethereum bridge and drained its full balance, forcing a service suspension.
Payy Network confirmed that an attacker exploited its Ethereum bridge contract around 04:21 UTC on September 24, 2026, and drained the contract's full balance. The company suspended the network and wallet, including deposits, withdrawals, transfers, and card transactions. Payy said the stolen assets were users' non-custodial deposits but has not disclosed the amount, attacker addresses, transaction hashes, or root cause. It notified law enforcement, exchanges, and blockchain analytics firms while tracing the funds.
- Payy said its Ethereum bridge contract was exploited and fully drained.
- The exploit occurred around 04:21 UTC on September 24, 2026.
- Network, wallet, deposit, withdrawal, transfer, and card services were suspended.
- Stolen funds were users' non-custodial bridge deposits; the amount is undisclosed.
- Law enforcement was notified, and the technical root cause is still unknown.
Full article560 words · extracted from gbhackers.com · click to collapse
Payy Network has confirmed that an attacker exploited its Ethereum bridge contract and drained its entire balance. As a result, the network and wallet services were immediately suspended.
This incident affected users’ non-custodial deposits held within the Payy Network and Payy Wallet bridge infrastructure.
The exploit occurred around 04:21 UTC on September 24, 2026. Payy disclosed that its Ethereum bridge contract was compromised and emptied, but has not yet released details on the technical root cause, the amount stolen, attacker wallet addresses, or transaction hashes.
“Payy’s bridge contract on Ethereum was exploited and drained of its full balance,” the company stated in a public incident notice. It added that its investigation is ongoing and that it is following established incident-response procedures.
Attackers Drain Payy Network
In response to the breach, Payy halted all network activities, which included:
- Deposits
- Withdrawals
- Transfers
- Card transactions
Payy also paused Wallet functionality while the company investigates the intrusion and determines next steps for affected users. Payy later confirmed that the stolen assets were users’ non-custodial deposits, emphasizing the impact of the bridge compromise on customer funds.
The term “non-custodial” generally means that users retain control of their private keys or wallet access, rather than entrusting their assets to a centralized custodian.
However, cross-chain deposits may still go through smart contracts or bridge liquidity pools, making them a high-value target if the contract logic, authorization process, validator system, or upgrade mechanisms are vulnerable.
Payy has notified law enforcement, cryptocurrency exchanges, blockchain analytics firms, and other relevant parties about addresses linked to the attacker.
The project is working with multiple incident-response organizations to trace the stolen funds and potentially prevent their conversion, bridging, or laundering through centralized exchanges and privacy-focused services.
The company has set out to pursue both fund-recovery efforts and a technical root-cause analysis. At the time of publication, Payy had not attributed the exploit to a specific threat actor or determined whether the compromise stemmed from a smart-contract vulnerability, stolen administrator credentials, compromised signer keys, flawed bridge validation, or another attack vector.
Payy’s initial disclosure did not specify whether the vulnerable bridge contract has been upgraded, disabled, or replaced. The broad suspension of transaction functionality indicates that the project is prioritizing containment while investigators assess the breach’s scope.
Blockchain bridges are frequent targets because they typically hold substantial pools of assets that represent value across different chains. An attacker who bypasses validation controls or manipulates withdrawal logic may mint unbacked tokens, submit fraudulent cross-chain messages, or withdraw locked collateral.
For users, this incident highlights the importance of evaluating bridge exposure separately from wallet custody. A self-custodial wallet can mitigate risks from centralized exchange failures. However, it does not eliminate smart-contract and protocol risks when assets are deposited into a cross-chain bridge.
Payy users should monitor the project’s official communications for verified recovery instructions and avoid unsolicited messages claiming to offer reimbursement, wallet migration, or fund recovery.
Attackers often exploit confusion following a crypto incident through phishing pages, fake support accounts, and malicious wallet-connection prompts. Payy has stated that it will continue to publish updates as the investigation progresses.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.