T
iTokenly

PAID Network hack — March 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 5, 2021
Target typeToken contract
Loss$3,100,000Price at time of incident
MethodPrivate key compromiseA single private key controlling upgrades to the PAID token's proxy contract was compromised. Ownership was transferred to the attacker, a new implementation adding burn and mint functions absent from the audited code was pushed through the proxy, ~60m PAID were burned and 59,471,745 minted, ~2.5m of which were dumped into the Uniswap PAID/ETH pool.
ChainsEthereum
Audited beforehandCertiK
OutcomeUsers reimbursed

What happened

PAID Network, an Ethereum token project building contract-automation tooling, lost control of its token contract on 5 March 2021.

According to CertiK, which had audited the project, the attacker took ownership of the upgradeable proxy behind the PAID token, pushed a new implementation containing burn and mint functions that were not in the audited code, burned roughly 60 million PAID and then minted 59,471,745 fresh tokens. About 2.5 million of those were sold into the Uniswap PAID/ETH pool, extracting 2,040.4339 ether before the team blocked PAID/ETH swaps. Cointelegraph put the realised proceeds at $3,104,887. Part of that was later clawed back: CoinChapter reported that several hundred ether was recovered and partially restored on the v2 contract, so the net loss was lower still.

Much larger figures circulate for this incident. Cointelegraph valued the full minted supply at about $180 million and Halborn at about $100 million, but those are notional valuations of tokens that were never sold and were subsequently invalidated. The PAID price fell more than 80 per cent within minutes, so the remaining supply could not have been realised at anything near those marks.

Whether this was an outside intrusion is disputed. PAID Network and CertiK both said no audited smart contract code was exploited and that the failure was key management. Nick Chong of ParaFi Capital pointed out on-chain that PAID's deployer address transferred contract ownership to the attacker around thirty minutes before the mint, and the account WARONRUGS had warned in January 2021 that the owner could mint tokens at will. No charges have been brought and no authority has named an actor, so the insider theory remains a researcher allegation.

PAID pulled liquidity, deployed a v2 token contract and restored holders' pre-hack balances by airdrop, invalidating the attacker's minted supply.

Sources

  1. CertiK (project auditor post-mortem)Primary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. CointelegraphSecondary · retrieved 2026-08-01
  4. CoinChapterSecondary · retrieved 2026-08-01

Official post-mortem: https://www.certik.com/resources/blog/paid-network-post-mortem

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "PAID Network hack — March 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/paid-network
https://itokenly.com/hacks/paid-network

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.