Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OnePlus OxygenOS Critical Flaws Let Zero-Permission Apps Gain Root Access
September 25, 2026
Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers
September 25, 2026
AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers
September 25, 2026
Home/CyberSecurity News/Critical Vulnerability in Payy Network Ethereum Bridge Led to Full Balance Drain
CyberSecurity News

Critical Vulnerability in Payy Network Ethereum Bridge Led to Full Balance Drain

Key Takeaways Payy Network’s Ethereum bridge contract was exploited, leading to the complete draining of its balance. The incident occurred on September 24, 2026, at approximately 4:21 UTC,...

Emy Elsamnoudy
Emy Elsamnoudy
September 25, 2026 3 Min Read
7 0

Key Takeaways

  • Payy Network’s Ethereum bridge contract was exploited, leading to the complete draining of its balance.
  • The incident occurred on September 24, 2026, at approximately 4:21 UTC, affecting user non-custodial deposits.
  • All Payy Network and Payy Wallet functions, including deposits, withdrawals, and transfers, have been temporarily suspended.
  • Law enforcement and blockchain analytics firms have been engaged to trace the stolen assets.

Payy Network has confirmed a significant security breach on its Ethereum bridge contract, resulting in the complete depletion of funds held within the contract. This critical exploit has forced the stablecoin payments platform to halt all network and wallet operations.

Table Of Content

  • Key Takeaways
  • Exploitation Details and Impact
  • Response and Mitigation Efforts
  • What You Should Do

Exploitation Details and Impact

The security incident took place on September 24, 2026, around 4:21 UTC. The compromised bridge contract facilitated asset transfers between the Ethereum blockchain and the Payy Network. Blockchain bridges are frequently targeted due to the substantial pooled funds they manage, which back assets moving across disparate networks. In this instance, the attacker successfully exploited the Ethereum-side of the bridge to siphon off all stored funds.

Payy has clarified that the stolen assets represent non-custodial user deposits linked to the Payy Network and Payy Wallet. This distinction is crucial, as these funds were not held in company-controlled custodial accounts but rather deposited by users via the bridge to access services within the Payy ecosystem. Following the exploit, Payy promptly suspended all major transaction activities across its network, encompassing deposits, withdrawals, transfers, and card transactions. Furthermore, Payy Wallet functionality has been paused as the company’s teams conduct a thorough investigation into the attack and formulate a recovery strategy for affected users.

A statement from Payy confirmed, “The bridge contract on Ethereum was exploited and drained of its full balance.” The company emphasized that its investigation is active and proceeding according to established incident-response protocols.

As of now, Payy has not disclosed specific technical details regarding the vulnerability exploited, the total value of assets stolen, the attacker’s wallet addresses, or the precise nature of the weakness—whether it was a smart-contract logic flaw, an authorization bypass, a compromised privileged key, or another type of vulnerability.

Response and Mitigation Efforts

In response to the breach, Payy has alerted law enforcement agencies, cryptocurrency exchanges, and blockchain analytics firms, providing them with the attacker’s wallet addresses. These measures are designed to facilitate the tracing of stolen assets, identify potential attempts to cash out funds, and prevent the attackers from moving the illicit gains through centralized exchanges or other traceable services.

This incident underscores the inherent security challenges associated with cross-chain bridges. These contracts frequently manage considerable cryptocurrency reserves and depend on intricate logic for validation, message passing, minting, and withdrawals. Even a minor flaw in these complex systems can allow attackers to forge withdrawals, bypass security checks, replay transactions, or transfer assets beyond their legitimate deposits.

What You Should Do

  • Avoid Interaction: Do not attempt to interact with the paused Payy Network bridge, wallet, or any related services until official recovery guidance is issued by Payy.
  • Stay Vigilant: Be extremely cautious of potential phishing attempts, impersonation campaigns, fake reimbursement pages, or malicious links purporting to offer refunds or token recovery.
  • Monitor Official Channels: Follow Payy’s official communications on X for verified updates on the investigation, technical details, and plans for user fund recovery or reimbursement.
  • Secure Other Accounts: If you used the same credentials for Payy Network on other platforms, consider changing those passwords as a precautionary measure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerphishingSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

New RSA Attack Bypasses Factoring Keys

Next Post

Bitget Hot Wallet Hacked: Attackers Steal $351.6 Million

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Sauron Loader Malware Evades Detection with DLL Side-Loading
September 25, 2026
Critical WordPress Comment2Shell RCE Vulnerability CVE-2022-0215 Patched
September 25, 2026
Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization
September 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us