Payy Network suspended its entire payments platform on September 24 after an attacker exploited a vulnerability in its Ethereum rollup contract and stole approximately $1.83 million in USDC. The exploit occurred at 04:21 UTC via a malicious transaction confirmed at block 26044909. Stolen funds were routed through the Railgun privacy protocol and converted to roughly 683 ETH before being distributed across multiple addresses. The team confirmed the attack and is working with law enforcement, with no timeline announced for resuming services or compensating affected users. A critical zk-circuit flaw had been patched in June, raising questions about whether additional attack surfaces were missed.
Source: Read the original article

