Payy Halts Network After $1.92 Million USDC Drain
Payments firm Payy halted activity on its network after attackers drained $1.92 million in USDC from the platform. The stolen funds were converted into approximately 683 ETH, with the majority moved onward to three separate wallets.
Why It Matters
The incident forced Payy to suspend deposits, withdrawals and card payments, disrupting customer access and highlighting ongoing security risks for crypto payment services. The rapid conversion and distribution of the funds complicates recovery efforts and tracking.
Key Facts
- Amount stolen: $1.92 million (USDC)
- Conversion: About 683 ETH
- Funds distribution: Most of the converted ETH was sent to three wallets
- Service status: Payy paused deposits, withdrawals and card payments
Payy has suspended core operations after an exploit led to the loss of $1.92 million in USDC from its network. According to reports, the attacker converted the initial proceeds into roughly 683 ETH before forwarding most of that ETH to three different wallets.
The company responded to the breach by pausing deposits, withdrawals and card payment functionality to contain the incident and prevent further outflows. Those actions effectively halted customer access to key services while the situation is being investigated.
Blockchain tracing shows the bulk of the converted funds were consolidated into three recipient wallets, a move that may make tracing and potential recovery efforts more complex. Payy has not yet announced details about the vulnerability exploited or a timeline for restoring services in the available excerpts.
The rapid conversion from USDC to ETH and subsequent distribution underscores common tactics used in crypto thefts to obscure provenance and accelerate movement of stolen assets. Payy's pause of transactional functionality reflects an immediate containment strategy used by platforms facing similar incidents.