On September 24, 2026, three distinct crypto projects experienced major security breaches that together wiped out more than $11 million in user and network assets.
Overview of the attacks
The incidents targeted different layers of the blockchain ecosystem. Payy Network, a service that handles on-chain payroll and treasury functions, saw its Ethereum bridge completely emptied. The gambling platform Duelbits lost a sizable amount of funds, while Meter.io, an EVM-compatible chain, was exploited to mint counterfeit tokens that were quickly sold on a decentralized exchange.
Payy Network bridge compromise
Payy reported that an adversary drained approximately $1.8 million from its bridge. Transaction analysis traced the stolen USDC to the privacy-focused protocol Railgun, after which the attacker swapped the assets for Ether. The breach affected non-custodial deposits belonging to Payy users, though the precise technical cause of the exploit has not been disclosed. In response, the team halted bridge operations and began a forensic review.
Duelbits private-key breach
Duelbits, a cryptocurrency betting service, disclosed losses in the vicinity of $7 million. Initial estimates placed the damage at $4.3 million, but further investigation across Bitcoin and Solana addresses raised the figure to nearly $6 million, and a co-founder later confirmed a total close to $7 million. The consensus among researchers points to a compromised private key as the primary vector, echoing a 2024 incident where the platform lost $4.6 million under similar circumstances. Duelbits has taken its platform offline pending a full audit and plans to relaunch a new version once security is assured.
Meter.io token-minting exploit
Unlike the other two cases, Meter.io’s breach did not involve stealing existing balances. Instead, the attacker exploited a flaw in the network’s block verification logic to generate about $2.3 million worth of unbacked tokens. These counterfeit assets were immediately dumped on PancakeSwap, causing the native MTR token to tumble nearly 80 percent and its counterpart MTRG to fall around 75 percent. Meter’s developers preserved the network state but have yet to outline a complete remediation strategy. The chain previously suffered a bridge exploit in 2022 that resulted in $4.4 million of losses.
Related security incidents
The day’s attacks coincided with a broader wave of irregularities. Bitget, a crypto exchange, reported unauthorized transfers amounting to roughly $351.6 million across a limited set of wallets, prompting a temporary suspension of withdrawals while investigations continue. Additionally, KelpDAO filed a lawsuit against LayerZero and co-founder Brian Pellegrino over a separate $292 million hack, alleging undisclosed vulnerabilities in the protocol’s architecture.
Why it matters
These coordinated breaches underscore the persistent challenges facing cross-chain bridges, private-key management, and consensus mechanisms. The rapid succession of high-value exploits highlights the need for rigorous audit practices, real-time monitoring, and stronger user safeguards across the decentralized finance landscape. As platforms scramble to address the fallout, the incidents may accelerate calls for standardized security frameworks and more transparent risk disclosures within the industry.




