Paxos Minted 300 Trillion PYUSD by Mistake — Then Burned It in 22 Minutes
On October 15, 2025, a Paxos operational key minted 300,000,000,000,000 PYUSD in one Ethereum transaction and burned the excess 22 minutes later. The number was a supply figure on the issuer's own address — never backed money, never in circulation.

3-Minute Fast Briefing
- The ParadoxAt 19:12 UTC on October 15, 2025, a Paxos operational key minted 300,000,000,000,000 PYUSD in a single Ethereum transaction, lifting the reported supply figure from about 1.33 billion tokens to more than 300 trillion — a bookkeeping number that never left Paxos's own address and was never backed by reserves.
- The Turning PointTwenty-two minutes later, the same key called the contract's burn function and destroyed the entire excess, returning total supply to its exact pre-error figure of 1,331,672,434.44 PYUSD; Paxos called the incident an internal technical error with no security breach.
- The LegacyThe episode showed that issuer-side mint authority — not the audited smart contract — is the decisive operational risk: one key could alter supply by 300 trillion, strengthening the case for multi-signature approval, hard mint caps, and independent checks.
Chronological Timeline
PayPal launches PYUSD on Ethereum — an ERC-20 token issued by Paxos and, by design, centrally minted and burned by the issuer.
A Paxos supply-controller key executes increaseSupply on the PYUSD contract, creating 300 trillion tokens for Paxos's own address in block 23585095.
The same key calls decreaseSupply, destroying all 300 trillion excess tokens and restoring supply to exactly 1,331,672,434.44 PYUSD — 22 minutes after the mint.
Paxos says the mint was part of an internal transfer gone wrong, that there was no security breach, and that customer funds are safe; Aave and other protocols reportedly pause PYUSD activity.
Technical reviews focus on why one operational address held mint authority and recommend contract limits, multiple signers, and frontend warnings for exceptional issuance.
1. One Transaction, 300 Trillion Tokens
On October 15, 2025, at 19:12:23 UTC, Ethereum block 23585095 confirmed a routine-looking transaction from a Paxos-controlled operational address to the PayPal USD contract. The call invoked increaseSupply, the token's mint function, with a value of 300,000,000,000,000 PYUSD — three hundred trillion tokens, created in a single confirmation and credited to Paxos's own key. PYUSD's on-chain total supply jumped from 1,331,672,434.44 tokens to 300,001,331,672,434.44.[2][4]
That number demands careful reading. PYUSD is an ERC-20 ledger with six decimal places: a mint changes the supply figure the contract reports, but by itself moves no dollars, creates no reserves, and transfers no value. The 300 trillion tokens were bookkeeping at Paxos's own address, not 300 trillion dollars of money or backing. The distinction between recorded supply, circulating supply, and reserve-backed supply is the center of this story.[7][4]
The mechanics were strikingly cheap. The mint consumed 66,722 gas at 10 gwei, or 0.000667 ETH. Wharton Finance's technical postmortem identified a one-million-fold gap between an intended 300 million PYUSD and the actual 300 trillion; because PYUSD uses six decimals, it described a plausible double-conversion mechanism while noting that Paxos's private frontend cannot be inspected. Halborn likewise reported the intended amount as 300 million.[2][7][6]
The anomaly was visible on block explorers, and observers split between two theories: a fat-finger mistake or a hack. The chain evidence favored the mistake. All 300 trillion tokens sat at the very Paxos address that had minted them; not one token moved to an external wallet, an exchange, or a DeFi protocol while the error was live. Whatever the ledger claimed, nothing had been sent anywhere.[7][2]
2. Twenty-Two Minutes: The Burn That Restored the Ledger
At 19:34:35 UTC, in block 23585206, the same Paxos key sent a second transaction calling decreaseSupply with the same value: 300,000,000,000,000. The contract recorded a Transfer to the zero address — the ERC-20 bookkeeping entry for destruction — and the entire excess ceased to exist. Total supply returned to exactly 1,331,672,434.44 PYUSD, the identical figure from 111 blocks earlier. Elapsed time from mint to burn: 22 minutes and 12 seconds.[3]
The chain record also settles what the excess touched. Immediately before the burn, the Paxos address held exactly 300,000,104,631,741.62 PYUSD — its pre-error balance of 104,631,741.62 plus the full mint. No fraction of the 300 trillion ever reached a user wallet, a market, or a redemption desk; the number was born inside the issuer's own account and died there. Nothing circulated, nothing was spent, and — by Paxos's own account of an internal technical error — no reserves ever stood behind it.[3][2]
"At 3:12 PM EST, Paxos mistakenly minted excess PYUSD as part of an internal transfer. Paxos immediately identified the error and burned the excess PYUSD."[1]— Paxos, official statement on X (October 15, 2025)
— Paxos, follow-up statement on X (October 15, 2025)
3. The Architecture of Trust: Who Holds the Mint Key
The incident was not a smart-contract exploit. PYUSD's audited contract executed exactly as designed — and its design concentrates creation in one place. Paxos's official repository describes PYUSD as an ERC-20 token that is centrally minted and burned by Paxos, the trusted party backing the token with U.S. dollars. October 15 was that design working, not failing — the failure lived in the human and procedural layer above it.[5]
Supply changes run through a separate SupplyControl contract. Only addresses holding the SUPPLY_CONTROLLER_ROLE — the supply controllers — may mint or burn, and the documentation notes that controllers can optionally carry rate limits capping how many tokens can be minted over a given time frame. On October 15, one operational key created 300 trillion tokens in a single call, so whatever limits governed that path stopped nothing. The same key then destroyed the full amount, proving that the power to create and the power to delete were one and the same.[5][2][3]
Halborn's post-incident assessment was stark: in the security firm's view, PYUSD's supply was managed by a single externally owned account with unlimited mint privileges, without a multi-signature wallet or built-in controls tying minting to reserves. Paxos's documentation completes the administrative picture: an owner can pause every transfer — yet even while paused, the supply controller keeps the ability to mint and burn — and an asset-protection role can freeze or wipe any address's balance outright.[6][5]
That backdrop frames the backing question. Paxos markets PYUSD as fully backed and publishes monthly transparency and attestation reports on its disclosures hub. The accidental tokens existed entirely outside that system: they appeared as a supply figure on an issuer-controlled address and were destroyed the same afternoon, with no dollars moved, redeemed, or transferred against them. In other words, the 300 trillion was an artifact of authority, not of assets — an editorial reading, but one the chain record makes hard to escape.[8][3]
4. Aftermath: The Number That Tested the Controls
The visible aftermath was reputational and precautionary. Halborn reported that Aave and other protocols froze PYUSD trading until conditions settled, even though none of the excess had reached a market. The sharper question was operational: how did a quantity one million times the intended amount clear a live issuance path controlled by the stablecoin's administrator?[6][7]
"Without a multi-signature wallet or built-in controls, it was possible to mint new tokens without appropriate reserves or other controls."[6]— Halborn, post-incident security analysis
Wharton Finance outlined boring but consequential mitigations: hard limits in the contract, time-window caps, multiple signers for unusually large mints, and frontend warnings when an issuance request exceeds plausible backing. Paxos's own repository says rate limits are optional for supply controllers. The incident therefore tests not whether controls are imaginable, but whether they are mandatory, independent, and sized to stop an administrator's mistake before finality.[7][6]
"Why does this address have mint authority? It’s clearly a Paxos hot wallet."[7]— Brett Hemenway Falk, Wharton Finance
Paxos could reverse the error quickly because every excess token remained at the issuer's own address: the issuer minted to itself, identified the mistake, and deleted it within minutes. The incident does not establish what would have happened if tokens had moved outward; it establishes that one operational authority could change supply by 300 trillion and then reverse it. The ledger returned to 1,331,672,434.44 PYUSD after 22 minutes in which no excess token could be spent.[2][3]
Key Takeaways for Investors & Builders
Mint Authority Is the Real Attack Surface
The PYUSD contract was never exploited; the operational path that controls it failed. A supply-controller key able to create 300 trillion tokens in one transaction is a single point of failure — which is why Halborn prescribed multi-signature control and built-in guardrails that tie minting to reserves.
Supply Is a Number; Backing Is a Fact
For 22 minutes PYUSD's reported supply exceeded 300 trillion tokens, yet none of the excess was circulating, redeemable, or reserve-backed. Reported supply, circulating supply, and backed supply are three different things — and this incident is the cleanest demonstration in stablecoin history of why investors must not conflate them.
Centralization Cuts Both Ways
The same unilateral authority that let one Paxos key create 300 trillion tokens also let that key delete them in 22 minutes. Fast correction and concentrated power were inseparable; stablecoin trust therefore depends on enforceable limits around the administrator, not only correct contract code.
Connected Stories in this Universe
Explore the chain reaction of historical breakthroughs, blunders, and legends.

The $235 Million WazirX Hack: Recovery Tokens, Not Guaranteed Repayment
A $235 million multisig breach froze an Indian exchange; court-supervised restructuring turned frozen balances into tokens — and Recovery Tokens that remain claims, not cash.
Read story →
Core Scientific: From Bitcoin Bankruptcy to the $9 Billion Deal Shareholders Rejected
After Chapter 11 in 2022, Core Scientific began converting mining infrastructure for AI — then shareholders rejected CoreWeave’s all-stock merger with roughly $9 billion of implied equity value.
Read story →
The German Government's 50,000 Bitcoin Panic Dump & The $2 Billion Paper Regret
How bureaucratic emergency liquidation rules forced German police to dump $2.8 billion in seized Bitcoin at the bottom—only to watch BTC surge to $100,000 weeks later.
Read story →Sources & References
- [1]Source 1: Paxos official statement on X (October 15, 2025)Paxos (X) · 2025-10-15Accessed 2026-08-23
- [2]Source 2: Etherscan — PYUSD mint transaction 0xc45dd1a7…c55b (block 23585095, October 15, 2025)Etherscan · 2025-10-15Accessed 2026-08-23
- [3]Source 3: Etherscan — PYUSD burn transaction 0xaa532ae7…4f4b (block 23585206, October 15, 2025)Etherscan · 2025-10-15Accessed 2026-08-23
- [4]Source 4: Etherscan — PayPal USD (PYUSD) token page, contract 0x6c3ea9…A0e23EtherscanAccessed 2026-08-23
- [5]Source 5: Paxos — pyusd-contract official repository (README: central mint/burn and SupplyControl design)Paxos (GitHub)Accessed 2026-08-23
- [6]Source 6: Halborn — Explained: The Paxos PYUSD Incident (October 2025)HalbornAccessed 2026-08-23
- [7]Source 7: Wharton Finance — Three Trillion PYUSD Minted (technical postmortem)Wharton Finance · 2025-11-13Accessed 2026-08-23
- [8]Source 8: Paxos — Transparency hub: PYUSD monthly attestation reportsPaxosAccessed 2026-08-23