# bridge exploit — X 热门讨论 (2026-09-24 12:50 UTC)
## @exvulsec (ExVul) · 09-24 10:13 · ♥26 ↻3 💬2 🚨 ALERT — Exploit on Ethereum
Payy @payy Network's L1 rollup bridge (RollupV1) was drained for ~$1.83M (1,828,589 USDC, ~95% of its USDC) in a single verifyRollup batch. The batch was sent by Payy's own prover key and signed by its own validator key.
Hidden among ordinary user withdrawals was one forged 1.83M USDC withdrawal to the attacker, the only one with an all-zero burn hash.
Root cause: RollupV1.verifyRollup keeps no deposit accounting and has no withdrawal cap or pause.
Once a batch has a valid proof and validator signature, it pays every burn message in it.
In Payy's public circuits (identical to the deployed verifier), a user can't produce a USDC withdrawal with a zero burn hash.
So the fake message got in during proving, not through a user bug: either the prover/validator setup was compromised, or the aggregate proof doesn't check which inner circuit it verified.
On L1 the attacker only ever deposited 10 USDC.
Attack tx: https://t.co/sg4kIL1sFI
Recipient: 0xAa4985dBDaBfACa344237D40F7E06C4a0BB57E70 Tx sender (Payy prover key): 0x5343b904bf837befb2f5a256b0cd5fbf30503d38
Victim (Payy Network RollupV1): 0x367C1eAF14AA06b78ce76bd0243297de79d85270
About 96.8k USDC is still in the rollup. @payy should remove the prover and validator keys before the next batch.
Subscribe to our TG bot for real-time attack alerts 👉 https://t.co/XXmb8rT3VA https://x.com/exvulsec/status/2103065252011397214