Three DeFi Exploits Swipe $11M from Payy, Duelbits, Meter in One Day

Three DeFi exploits siphoned off more than $11 million in 24 hours
Table of Contents

TL;DR:

  • On September 24, 2026, three independent security incidents accumulated combined losses exceeding $11 million.
  • The Duelbits platform recorded the day’s largest theft, with nearly $7 million drained from its hot wallets.
  • The Meter.io and Payy Network protocols suffered losses of $2.3 million and $1.8 million, respectively, through verification flaws and bridge vulnerabilities.

The DeFi sector experienced a critical day this Thursday, September 24, when a series of exploits compromised the corporate security of Payy Network, Duelbits, and Meter.io.

Payy Network was the first to report. The protocol provides on-chain payroll and treasury management solutions. The firm confirmed the total drain of balances on its Ethereum bridge, prompting an emergency system shutdown.

According to alerts published by on-chain investigator Specter, the attacker used the privacy protocol Railgun to fund the initial operation. Subsequently, they converted the stolen $1.8 million in USDC into Ethereum units. The company stated that the assets corresponded to non-custodial deposits belonging to users of its wallet and platform.

Just hours later, another exploit occurred. The casino and sportsbook Duelbits suffered a security breach affecting its hot wallets across multiple blockchains.

The security team at Scam Sniffer detected anomalous capital outflows from operational wallets on Ethereum, BNB Chain, Tron, and Bitcoin. While preliminary estimates by analytics firms like PeckShield placed the theft at $4.3 million, Duelbits co-founder Joe confirmed final losses close to $7 million.

Technical records from Etherscan show that the compromised address transferred stablecoin and token balances before being left with less than $25 in ether. A report from CoinLaw suggests that the root cause points to private key exposure, allowing the attacker to sign legitimate transactions without needing to exploit a smart contract. Following the outflows, the hacker consolidated 2,234 ETH into a single address.

Three DeFi exploits siphoned off more than $11 million in 24 hours

Bridge Breaches and Illicit Asset Minting

The day’s third event affected the EVM-compatible network Meter.io, differing from the previous incidents in its execution mechanics.

Cybersecurity firm Blockaid reported that the attacker exploited a vulnerability in the block verification mechanism to mint unbacked tokens. Following the unauthorized issuance of assets valued at $2.3 million, the funds were liquidated through the decentralized exchange PancakeSwap.

Market pricing data showed an immediate collapse across the Meter ecosystem following the sale of the illicitly minted tokens. The MTR token dropped nearly 80%, while the governance asset MTRG fell approximately 75% in the last 24 hours.

The Meter.io development team stated that they managed to halt network state to prevent further operations, though official documentation has not yet specified the technical process for restoring the original balances.

Both Meter and Duelbits have prior technical records of infrastructure compromises. Meter.io suffered a $4.4 million bridge exploit in 2022, while Duelbits faced a $4.6 million drain in 2024 linked to key leaks reported by auditing firms like CertiK.

Incident audits remain active, and the technical restoration of Duelbits services remains contingent on hot wallet replenishment and the completion of forensic investigations over the coming days.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews