Finance.Yahoo Over $11M Lost in Crypto Hacks Targeting Payy Network, Duelbits, and Meter
Article Content
- •Three crypto projects lost over $11M in a single day due to hacking incidents.
- •Payy Network halted operations after $1.83 million was stolen via an Ethereum rollup exploit.
- •Duelbits reported losses of around $7 million, likely from a compromised private key.
On September 24, 2026, three cryptocurrency projects were hacked, resulting in losses exceeding $11 million. Payy Network reported a theft of $1.83 million in USDC due to an exploit in its Ethereum rollup contract. The attacker used a malicious transaction to drain funds and laundered them through the Railgun privacy protocol. Duelbits, a gambling platform, suffered losses of approximately $7 million, likely due to a compromised private key. Meter.io experienced an attack where the hacker minted $2.3 million in unbacked tokens by exploiting a flaw in block verification. The incidents affected various crypto infrastructures, including bridges and private keys. Payy Network has suspended operations and has not disclosed a timeline for resuming services. The attacks coincide with a larger incident involving Bitget, which reported unauthorized asset transfers totaling $351.6 million.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Bitget in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…