Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Payy Network has confirmed that attackers exploited its Ethereum bridge contract and drained the contract’s entire balance, forcing the stablecoin payments platform to suspend network and wallet functions.

According to a public statement from Payy, the incident occurred at approximately 4:21 UTC on September 24. The affected bridge contract supported transfers between Ethereum and the Payy Network.

Blockchain bridges are high-value targets because they often hold pooled funds that back assets moved across different networks. In this case, the attacker exploited the Ethereum-side contract and removed all funds held in the bridge balance.

Payy said the stolen assets were users’ non-custodial deposits connected to Payy Network and Payy Wallet. This distinction is important because the funds were not held in a traditional custodial account controlled directly by the company.

Hackers Exploited Ethereum Bridge Contract

Instead, users had deposited funds through the bridge mechanism to access services on the Payy ecosystem. Following the exploit, Payy halted all major transaction activity across its network. The temporary suspension includes deposits, withdrawals, transfers, and card transactions.

The company also paused Payy Wallet functionality while its teams investigate the attack and determine the appropriate next steps for affected users.

“The bridge contract on Ethereum was exploited and drained of its full balance,” Payy said, adding that its investigation remains ongoing and that it is following incident-response procedures.

The company has not yet disclosed the vulnerability type, the amount stolen, the attacker’s wallet addresses, or whether the exploit resulted from a smart-contract logic flaw, an authorization bypass, a compromised privileged key, or another weakness.

Payy said it has notified law enforcement, cryptocurrency exchanges, blockchain analytics firms, and other relevant organizations about the attacker addresses.

These actions are intended to help trace the stolen assets, identify potential cash-out attempts, and prevent the attackers from moving funds through centralized exchanges or other identifiable services.

The incident highlights the continuing security risks surrounding cross-chain bridges. Bridge contracts commonly manage large pools of cryptocurrency and rely on complex validation, message-passing, minting, and withdrawal logic.

A single flaw in these systems can enable an attacker to forge a withdrawal, bypass verification checks, replay a transaction, or transfer assets beyond the amount legitimately deposited.

For Payy users, the immediate priority is to avoid interacting with the paused bridge, wallet, and network services until the company releases verified recovery guidance.

Users should remain alert for impersonation campaigns, phishing messages, fake reimbursement pages, and malicious refund or token recovery links, while Payy continues posting investigation updates on X as its investigation progresses.

The company’s next disclosures will be closely watched for technical details on the attack path, the value of the stolen assets, affected deposit records, and plans to reimburse or recover user funds.

Payy confirmed that the Ethereum bridge was exploited at 4:21 UTC and that all Payy Network transaction functions were paused during the response.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network appeared first on Cyber Security News.