Three crypto projects were exploited on Thursday in a string of incidents that together cost more than $11 million. The affected platforms were Payy Network, Duelbits and Meter, with reported losses of about $1.8 million, $7 million and $2.3 million respectively.
The breaches affected different parts of the crypto stack, from a payroll-focused rollup bridge to a gambling platform and an EVM blockchain. In each case, the teams disclosed disruptions and began investigations, but the exact recovery path was not immediately clear.
Payy bridge drained and operations paused
The first incident involved the bridge between Payy Network and Ethereum. Payy describes itself as a rollup offering on-chain payroll and treasury services. Suspicious withdrawals were initially flagged in the project’s Telegram group by the pseudonymous on-chain investigator Specter.
According to the reported fund flows, the attacker used Railgun, a privacy protocol, for funding and then swapped roughly $1.8 million in USDC into ETH. Payy later confirmed that the exploit had emptied the full balance held in its bridge and said it had paused operations.
The company later clarified that the lost assets were users’ non-custodial deposits to Payy Network and Payy Wallet. As of the source report, the team had not disclosed the underlying cause of the exploit.
Duelbits says roughly $7 million was lost
The second case hit Duelbits, a crypto casino and sports betting platform, in what was described as a private key compromise. Early loss estimates changed as investigators tracked additional affected addresses across multiple chains.
Blockchain security firm PeckShield first put the damage at about $4.3 million. Specter later raised the estimate to $4.9 million and then $5.9 million after identifying impacted Bitcoin and Solana addresses. Duelbits co-founder Zyro ultimately said the final figure was approximately $7 million.
The same update said the platform would remain offline while the investigation continues. Duelbits also stated that user funds are safe, and outlined its next steps as completing the investigation, re-topping hot wallets, restoring service and launching what it called Duelbits 2.0.
Meter links exploit to validation flaw
The third incident affected Meter.io, an EVM blockchain whose team said the problem stemmed from a block validation flaw. Unlike the Payy exploit, the attack did not drain existing bridge deposits. Instead, it allowed the creation of unbacked tokens.
Meter said tokens worth a reported $2.3 million were minted and then sold on PancakeSwap. Those sales pushed down the prices of both MTR and MTRG. In a post on X, the team said it had preserved the chain state but had not yet decided on a recovery method.
A concentrated day of losses
Taken together, the three incidents made Thursday an unusually costly day even by the standards of a sector that has continued to face regular exploits. The attacks also highlighted different failure points: a bridge draining event at Payy, a reported private key compromise at Duelbits, and a validation flaw at Meter that enabled token minting.
The next confirmed steps are limited to what the projects themselves have said. Payy has paused operations while it works to determine the cause, Duelbits plans to stay offline until its investigation is complete, and Meter says recovery is still under discussion after preserving chain state. Meter has also previously suffered a bridge-related hack, losing $4.4 million in 2022.
Source: protos.com