Payy Rules Out a Stolen Key After $1.92 Million in User Deposits Drained From Its Bridge

payy rules out a stolen key after 1 92 million in user deposits drained from its bridge It took just two transactions, sent roughly five hours apart to one address, to strip about $1.92 million in USDC out of Payy's Ethereum bridge. According to the company, a stolen key was not to blame.Image Source: PAYYImage Source: PAYY

It took just two transactions, sent roughly five hours apart to one address, to strip about $1.92 million in USDC out of Payy’s Ethereum bridge. According to the company, a stolen key was not to blame.

Payy operates a network built for private stablecoin payments. In a Friday post on X, it said its initial root cause analysis showed the drain “was NOT a compromised key, social engineering or exploit of our off-chain infrastructure.” The findings themselves have not been released. Payy says an audit firm is reviewing them first.

That creates an uncomfortable gap. Payy has ruled out the three most common explanations for a bridge drain, but it has not said what actually caused this one.

Users’ money was taken

The loss did not come from Payy’s treasury. The company confirmed the stolen funds were “users’ non-custodial deposits to Payy Network / Payy Wallet.” The network and Payy Wallet have both been paused.

In its first statement, Payy said its bridge contract “was exploited and drained of its full balance” at 4:21 UTC on Sept. 24. Deposits, withdrawals, transfers and card transactions were all put on hold. The bridge is a rollup contract that settles the network’s activity on Ethereum, so every user’s funds end up there.

The on-chain record

A review of the Ethereum records gives a clearer picture than Payy’s own posts. At 4:21 UTC, the first batch moved 1,828,589 USDC to a single address, leaving about $95,000 in the bridge.

Around five hours later, at 9:30 UTC, a second batch sent a further 90,202 USDC to that same address. About $700 was left behind.

Both payouts ran through verifyRollup, the function Payy uses to post batches of network activity to its bridge. Both were submitted by the address that posts those batches. Nothing about that address’s behavior looked out of the ordinary: each of the last 200 transactions it sent, stretching back to late August, was a verifyRollup call to the bridge.

In other words, the funds left through Payy’s own settlement path, submitted by Payy’s own batch-posting address. Payy says that address’s key was not compromised. Based on what is public so far, it is difficult to see any other way this could have happened.

A small test, then the main event

Payy had seen the receiving address before. On Sept. 22 it deposited 5 USDC and withdrew 5 USDC later the same day. It deposited another 5 USDC on Sept. 23.

The funds moved quickly after the first payout. Within roughly eight minutes they had been sent to a second address and sold through UniswapX for about 683 ETH. By 5:39 UTC, nearly all of that ether was held in three wallets.

The second payout was handled differently. As of Friday afternoon, the 90,202 USDC was still in the receiving address.

The questions Payy has left open

Payy said it has flagged the attacker’s addresses to law enforcement, exchanges and blockchain analytics firms. It paused Payy Wallet and said it would share details on next steps for users. The company said it aims to publish a validated report “in the next few days.”

What depositors most want to know is missing from its posts. Payy has not given a loss figure, has not said whether users will be repaid, and has not said when the network will come back online.

The drain also came on an eventful day. On the same day, Bitget said about $351.6 million was taken from its hot and warm wallets in an unrelated incident.

Anyone with funds on Payy has no options for now, as deposits, withdrawals and transfers are all frozen. The key thing to watch is whether the audited report explains how verifyRollup released money that nobody authorized. The other is what becomes of the 90,202 USDC that was still untouched as of Friday afternoon.