Payy Network has published a technical post-mortem for the September 24 exploit of its bridge contract, and the conclusion points away from stolen keys and toward the cryptography itself. According to the project's official account, an attacker submitted an invalid burn proof that Payy's deployed Noir and Barretenberg verifier accepted as valid. Two transactions moved roughly 1.92 million USDC out of the Payy rollup to a single receiving wallet, confirmed on-chain in Ethereum block 26,044,909 at 04:21 UTC on September 24.

The finding, first reported in detail by SpendNode and consistent with Unchained's earlier reporting that ruled out a private-key compromise, matters beyond one card issuer: the flawed component sits in Aztec's Noir/Barretenberg proving stack, not in code Payy wrote.

Two Burns, One Wallet

The post-mortem breaks the drain into two withdrawals. The first burn released 1,828,589.37 USDC from the Payy rollup even though the underlying transaction was invalid. A second burn of 1 USDC — paid early by a burn substitutor and later reimbursed — released a further 90,202.82 USDC to the same wallet.

Payy confirmed the stolen funds were users' non-custodial deposits, halted transfers, withdrawals and card payments, and paused Payy Wallet. The network has remained suspended while remediation proceeds. Stolen funds were routed through the Railgun privacy protocol, complicating recovery, Crypto Briefing reported at the time of the incident.

What Broke, and Who Owns It

Payy uses zero-knowledge proofs to keep spending private while proving funds exist and have not been double-spent. The verifier is the on-chain checkpoint that checks those proofs before releasing money. When it accepts a proof it should have rejected, the bridge's entire security model collapses at that single point — the private keys stayed safe, the proof check did not.

Because the vulnerable verifier is developed by Aztec as part of the Noir toolchain, the concern extends to any project relying on the same verifier code path until a patch is confirmed. That makes this closer in shape to a supply-side flaw in widely used ZK infrastructure than to a garden-variety smart-contract bug in a single application.

What to Watch Next

Payy says a full report accompanies the post-mortem. The checkpoints that would close this incident out are: a confirmed patch to the verifier, an independent human-reviewed audit of the fix, and a restitution plan for the drained liquidity. Until those land, the bridge should be treated as under repair, and holders should keep exposure to any network using the unpatched verifier stack minimal.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.