Incident
Published 2026-09-24
Verified 2026-09-27

Payy Network (24 Sep 04:21 UTC): Ethereum bridge contract drained of full balance; network/wallet paused

Payy (@payy_link) stated on X that at approximately 04:21 UTC on 24 September 2026 its Ethereum-side bridge contract (Ethereum ↔ Payy Network) was exploited and drained of its full balance. Stolen assets were described as users’ non-custodial deposits tied to Payy Network / Payy Wallet (not a traditional company-custodial hot wallet). Payy paused deposits, withdrawals, transfers, card transactions and Payy Wallet while following incident-response procedures; it reported notifying law enforcement, exchanges and blockchain analytics firms about attacker addresses. Amount stolen, exact vulnerability class (logic flaw vs auth bypass vs privileged key), and attacker addresses were not disclosed in the initial statement. Wire amplify: Cyber Security News 25 Sep. Primary: Payy X incident statement.

Product
Payy Network / Payy Wallet (Ethereum bridge contract)
Versions
n/a (bridge incident; vuln class / loss amount not yet published)
Exploited in Australia?
unknown
Patch to
Users: treat Payy channels as paused; watch only official @payy_link updates; expect phishing. Bridge operators generally: freeze/pause on anomaly, rotate privileged keys, engage chain analytics early.

Primary: Payy (@payy_link) — Ethereum bridge drained (X, 24 Sep 2026) · Vendor: Payy (company incident statement on X) · Cyber Security News — Payy bridge drain (25 Sep 2026)

breaches cloud