Three crypto projects lost more than $11M in one day, including Payy Network, Duelbits, and Meter
On September 24, three crypto projects were hit in separate attacks and ended up with combined losses of more than $11M. For high-risk operators, the useful bit is not the drama — it is that the failures hit different layers of infrastructure: a bridge, a betting platform, and token issuance on an EVM chain.
- Payy Network said its Ethereum bridge was compromised and that the network was halted after the attack. Onchain researcher Specter flagged suspicious transactions from the bridge, saying the attacker first moved funds through Railgun and then swapped the stolen $1.8M in USDC for Ethereum.
- Payy Network later said the bridge had been completely drained. The company said the funds were non-custodial deposits belonging to Payy Network and Payy Wallet users, but it has not disclosed the exact cause of the exploit.
- The next target was Duelbits, a cryptocurrency gambling and betting platform. PeckShield initially estimated losses at $4.3M, then Specter widened the tally to $4.9M and later $5.9M after finding additional affected addresses on the Bitcoin and Solana networks. A Duelbits co-founder eventually put the losses at around $7M, most likely because of a compromised private key.
- Duelbits had already been attacked in 2024, when it lost $4.6M in an incident that CertiK also linked to a potential private key leak. For PSPs and acquiring teams, that is the line that matters: the same operator has now shown repeated key-management exposure, which is a different problem from a one-off smart contract bug.
- The third incident hit Meter.io, an EVM blockchain. The attacker minted $2.3M in unbacked tokens, adding another failure mode to the day’s list: not stolen reserves, but broken token integrity. The source text says the attack affected the Meter network and that two of the three projects had already suffered major hacks in previous years.
In one day, the losses crossed $11M, and the spread of incidents was the point: bridge compromise, private key risk, and unbacked minting. If you run payments into high-risk crypto flows, that is the shortlist of failure types you need to model, because they tend to show up where controls are weakest and where recovery is slow.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!