ADVERTISEMENT
ADVERTISEMENT
EGW-NewsPayy, Duelbits Hacked Same Day for $1.8M, $4.3M
Payy, Duelbits Hacked Same Day for $1.8M, $4.3M
161
Add as a Preferred Source
0
0

Payy, Duelbits Hacked Same Day for $1.8M, $4.3M

Two unrelated crypto platforms got drained within hours of each other on September 24, and together they're a decent snapshot of where the industry's security problems actually sit right now.

Payy: the entire balance, gone

Payy Network, a privacy-focused stablecoin payments protocol, confirmed that its Ethereum rollup contract had been hacked. Not partially skimmed — the entire balance was taken. Investigators at Specter first flagged roughly $1.8 million in USDC leaving the protocol; Payy's own confirmation put the figure closer to $1.83 million once the ETH conversion was tallied.

The attacker funded gas for the operation through Railgun, the privacy mixer, before draining the rollup. The stolen USDC was swapped into about 683 ETH and split across three addresses, the standard first move before laundering. Payy has since suspended deposits, withdrawals, transfers, and card transactions across the network, and says it's notified law enforcement and brought in outside incident-response firms.

What stands out isn't the exploit's sophistication. Early classification points to an access-control failure on the bridge and rollup interface, not a novel cryptographic trick. Just a permission that shouldn't have been open.

Duelbits: a repeat customer

Crypto casino Duelbits went offline the same day after PeckShield flagged roughly $4.3 million in suspicious outflows across Ethereum and BNB Chain: 836 ETH (~$2.23M), 1.146 million USDT, 209 BNB (~$160.7K), 96,805 USDC, 12.4 billion SHIB (~$70.2K), and 31,515 DAI. The attacker routed the haul through deBridge and Relay's Router V3, then consolidated most of it into roughly 1,588 ETH while leaving the DAI largely untouched.

Duelbits hasn't disclosed how access was obtained, and it's still unclear whether player balances were affected — only that hot wallets were hit. Scam Sniffer's tally came in a touch lower, around $4.2 million, but the firm flagged that Tron wallets were drained too; later on-chain activity involving Bitcoin and Solana pushed some estimates toward $5.9 million before things settled down. The working theory is a leaked private key, not a contract bug.

This isn't Duelbits' first time here. The casino lost $4.64 million in February 2024 in an incident CertiK attributed to a compromised private key, with the attacker exploiting a double-counting flaw in a token contract's balance logic. Two major hacks, roughly 18 months apart, both tracing back to key or access failures rather than some exotic new attack vector. That pattern alone says something about how much work hot-wallet operators still have ahead of them.

The bigger picture

Zoom out and the timing lines up with a trend security firms have been flagging all year. Immunefi counted 207 hack incidents in the first half of 2026, a record, for roughly $972 million lost. CertiK's tally for the same stretch landed closer to $1.32 billion. The gap between those two numbers matters less than what both firms agree on: attackers have largely moved up the stack. Smart-contract bugs are harder to find now, thanks to continuous audits and bug bounty programs, so the money has followed the path of least resistance into infrastructure, leaked keys, misconfigured bridges, and privileged access that was never locked down properly.

Don’t miss esport news and update! Sign up and recieve weekly article digest!
Sign Up

Payy and Duelbits, hit hours apart by two different methods, both land squarely in that bucket. Neither company has published a full post-mortem yet, and the figures on both incidents could still move as investigators keep tracing the funds.

ADVERTISEMENT
Leave comment
Did you like the article?
0
0

Comments

ADVERTISEMENT
FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER