A Single Key and a Decimal Slip Sent PYUSD Supply to $300 Trillion
On Wednesday, October 15, at 3:12 PM EST, Paxos executed an internal transfer that briefly minted $300 trillion in PayPal's PYUSD stablecoin on Ethereum — an amount more than 2.5 times the size of the entire world's GDP, created and later destroyed for a combined gas cost of about $2.66. For roughly 22 minutes, PYUSD's on-chain supply implied it held more notional value than any asset class in existence, before the tokens were sent to a burn address and removed from circulation.
Nothing about the incident involved a hack or an exploit. The smart contract behaved exactly as coded; the error was in the input. What the episode exposed instead was that a single Externally Owned Account (EOA) held unrestricted authority to mint and burn PYUSD — no multi-signature requirement, no caps, no additional approval step.

01What was supposed to happen
The intended operation was a $300 million internal transfer between Paxos wallets — routine treasury housekeeping. Instead, a decimal-place error turned the instruction into a mint order six orders of magnitude larger than planned, and the network processed it exactly as instructed, adding $300,000,000,000,000 to PYUSD's supply.
02The transaction sequence
The chain of events began normally: 300 million PYUSD was burned in one transaction (0xe9faf15455483e9503df599140550f19f4fa7e9dd3fdaed6ccfd597c64e80db2), followed by a transfer of another 300 million between internal wallets (0xd6343c3d44f53edc524a72d64c819854929703d35c72afb071afe4fae0b84db2).
The next instruction was where the error occurred: a mint of $300 trillion (0xc45dd1a77c05d9ae5b2284eea5393ecce2ac8a7e88e973c6ba3fe7a18bf45634), credited straight to Paxos's own treasury. That was followed by a burn removing the same $300 trillion from supply (0xaa532ae7f06cccdbdc226f59b68733ae8594464a98e128365f8170e305c34f4b). Immediately after, Paxos minted another 300 million PYUSD (0x5b40975ea1326d1b48cb974d0fe1b8529b09a907c0a25833529e06cc60151abd), apparently to complete the originally intended transfer.
The EOA behind all of these transactions was 0x2fb074FA59c9294c71246825C1c9A0c7782d41a4.
03Market reaction
Even though the excess supply existed on-chain for only about 22 minutes, Aave froze its PYUSD markets as a precaution once the anomaly became visible. The timing was awkward for Paxos, which is currently pursuing a national trust charter from the OCC — a process that depends on regulators trusting the firm's operational controls.

Amanda Fischer, formerly chief of staff to SEC Chair Gary Gensler, summarized the regulatory concern this way: "If someone with a fat finger error can increase the total supply of a stablecoin by a factor of 120,000, then perhaps regulators should proceed cautiously with granting that firm... the keys to the payment system."
04The underlying issue
Commentators drew comparisons to other historical episodes of runaway money creation — including Zimbabwe's multi-year hyperinflation, which took years to unfold rather than minutes — to underscore how unusual it was for an amount of this scale to appear and disappear so quickly and so cheaply. But the core takeaway is narrower and more concrete: PYUSD's mint-and-burn authority rested on a single private key rather than any multi-party control, meaning one mistaken keystroke was sufficient to create — however briefly — more nominal value than exists in the global economy. The code executed exactly as designed; the design itself was the point of failure. For a stablecoin issuer actively seeking expanded regulatory trust, the episode became a live demonstration of exactly the kind of operational risk regulators are meant to guard against.
Get new scam files the moment we publish them — usually 2–3 emails a week.