Payy Network recently experienced a significant security breach when hackers exploited its Ethereum bridge contract, leading to a complete draining of the contract’s funds. This incident prompted the suspension of all network and wallet functionalities for the stablecoin payments platform.
Details of the Exploit
The breach was officially reported by Payy, stating that the attack took place around 4:21 UTC on September 24. The compromised bridge contract facilitated transactions between Ethereum and the Payy Network, making it a prime target due to the pooled funds it managed.
In this incident, the attackers targeted the Ethereum-side contract, successfully extracting all assets contained within. These were non-custodial deposits linked to Payy Network and Payy Wallet, highlighting a key distinction from traditional custodial accounts directly managed by the company.
Impact and Response
Following the exploit, Payy immediately suspended all major transaction activities, including deposits, withdrawals, transfers, and card transactions. The Payy Wallet was also put on hold as the company’s teams worked diligently to investigate the breach and decide on appropriate measures for impacted users.
Payy acknowledged that the investigation is ongoing and that it is adhering to established incident-response procedures. The exact nature of the vulnerability exploited, the total amount stolen, and specifics such as the attacker’s wallet addresses have not yet been disclosed.
Security Measures and Future Outlook
In response to the attack, Payy has engaged with law enforcement, cryptocurrency exchanges, and blockchain analytics firms to help trace the stolen funds and monitor for any cash-out attempts. This collaboration is aimed at preventing the attackers from moving the assets through centralized exchanges.
The incident underscores the persistent security challenges associated with cross-chain bridges. These contracts often manage substantial cryptocurrency holdings and depend on intricate logic for validation, message-passing, and withdrawals. A single flaw can significantly impact the system’s security.
For Payy users, it’s crucial to refrain from interacting with any network services until official recovery guidance is provided. Users should be vigilant against potential phishing scams or fraudulent recovery offers while awaiting further updates from Payy on their investigation progress.
