Payy Network Hacked for US$1.83 Million in USDC

A privacy stablecoin payments protocol lost about US$1.83 million overnight. What was taken, how, and what it means for money you leave in any payment app.

Share
Payy Network Hacked for US$1.83 Million in USDC

Quick answer: Payy Network was hacked on 24 September 2026. An attacker drained about US$1.83 million in USDC from its Ethereum rollup contract, swapped it into 683.38 ETH and split it across three addresses. Public incident records classify it as a failure of access control in the contract, not an attack on users.

Key takeaways

  • How much: about US$1.83 million in USDC, converted to 683.38 ETH and sent to three addresses.
  • When: 24 September 2026, flagged by the security firm PeckShield.
  • How: unauthorised withdrawals through the rollup interface. The public classification is an access control exploit.
  • What users could have done: nothing at the time. The exposure came from holding a balance inside the contract.

Payy Network, a privacy-focused stablecoin payments protocol, lost about US$1.83 million to an attacker on 24 September 2026. Here is what is known, and what it means for money you leave inside any payment app.

What happened

An attacker targeted Payy Network's rollup interface on Ethereum and executed unauthorised withdrawals of roughly US$1.83 million in USDC.

  • The stolen USDC was swapped into 683.38 ETH and split across three addresses.
  • The attacker had funded the gas for the operation through the Railgun privacy protocol beforehand.
  • PeckShield flagged the transfers. Payy confirmed a cross-chain contract attack and began work on patching the rollup bridge.
  • Public incident records classify the cause as an access control exploit, not phishing.

No technical post-mortem has been published yet, so anyone describing the exact mechanism right now is guessing.

What it means for users

This was a contract failure, not a user failure. Nobody could have avoided it by being careful with links or passwords. The exposure came from holding a balance inside the protocol when it broke.

The same is true of every pooled contract, bridge and payment app. The amount you leave inside one is the amount you are putting at risk of its worst day.

Two hacks in two days

The Payy exploit landed on the same day as a far larger one. Together they show the two ways crypto money disappears.

Payy NetworkBitget
Date24 September 202624 September 2026
Amountabout US$1.83 millionabout US$351.6 million
What brokeaccess control in a rollup contracthot and warm wallet infrastructure
User fundsno protection fund announcedcovered by a US$464 million fund, per the company
Access to fundscontract balance drainedwithdrawals paused pending review

A small protocol with no backstop and a large exchange with one both leave the user in the same position on the day: the money is not where you can reach it. That is the argument for holding only what you are spending inside any platform.

Five checks worth doing tonight

  1. Keep only what you plan to spend inside any payment app or bridge.
  2. Revoke token approvals for contracts you no longer use.
  3. Keep the wallet on your phone separate from the wallet holding your savings.
  4. Check the domain every time. Phishing rises sharply in the days after any public incident.
  5. Write down which contracts actually hold your money. Most people cannot list them.

Security firms counted 207 hacks in the first half of 2026, with losses estimated between about US$972 million and US$1.32 billion. The biggest ones came from stolen keys and social engineering, not exotic bugs.

Where Fizen stands

Fizen is not connected to Payy Network and was not affected. Fizen is non-custodial, so balances sit in wallets users control.

We will not claim immunity. Nobody in this industry can promise that no incident will ever happen. What we can say is why features here ship late or not at all: if a flow moves user funds and we are not confident in how it fails, it waits for the security review, and if a market's rules are unclear it waits for the legal one. Fizen is not offered to US Persons, which is one of those decisions.

The trade for self-custody is blunt. Nobody, Fizen included, can restore a recovery phrase you lose.

Frequently asked questions

How much did Payy Network lose?

About US$1.83 million in USDC, drained from its Ethereum rollup contract on 24 September 2026.

Where did the money go?

It was swapped into 683.38 ETH and split across three addresses, a common pattern before laundering.

Was it a phishing attack on users?

No. Public incident records classify it as an access control exploit in the contract.

Is Fizen affected?

No. Fizen is a separate, non-custodial app and is not connected to Payy Network.

What should I do now?

Keep only spending money inside payment apps, revoke unused token approvals, and ignore any message offering recovery or compensation.

Your keys, your balance, your call

Fizen is a non-custodial USDT app: the balance stays in a wallet you control, with an investment from Tether in the company. Nobody, Fizen included, can restore a lost recovery phrase. Availability depends on your country and partners. Not offered to US Persons.

See how the wallet works

Terms and conditions

  • Information only. This article reports a publicly documented security incident and general security practice. It is not an offer or sale of any product or service, and it is not financial, legal or tax advice.
  • For readers in the United States. This article provides information only. It is not an offer, solicitation or sale of any product or service, and it is not financial, investment, legal or tax advice. Fizen is not offered to US Persons.
  • Independent. Fizen is not affiliated with, endorsed by or a partner of Payy Network, PeckShield, Railgun, TRM Labs or CertiK. The incident details here are what public reports stated on 24 September 2026 and may be revised as the investigation continues.
  • Full terms. See the Master Terms of Use, Privacy Policy and Disclaimer on the Fizen website.

Sources

Reported on 24 September 2026, the day of the incident. Figures may be revised as the investigation continues.