
Payy ve Duelbits aynı gün 1,8 milyon dolar ve 4,3 milyon dolarlık hırsızlık olayına maruz kaldı.
Two unrelated crypto platforms got drained within hours of each other on September 24, and together they're a decent snapshot of where the industry's security problems actually sit right now.
Payy: the entire balance, gone
Payy Network, a privacy-focused stablecoin payments protocol, confirmed that its Ethereum rollup contract had been hacked. Not partially skimmed — the entire balance was taken. Investigators at Specter first flagged roughly $1.8 million in USDC leaving the protocol; Payy's own confirmation put the figure closer to $1.83 million once the ETH conversion was tallied.
The attacker funded gas for the operation through Railgun, the privacy mixer, before draining the rollup. The stolen USDC was swapped into about 683 ETH and split across three addresses, the standard first move before laundering. Payy has since suspended deposits, withdrawals, transfers, and card transactions across the network, and says it's notified law enforcement and brought in outside incident-response firms.
What stands out isn't the exploit's sophistication. Early classification points to an access-control failure on the bridge and rollup interface, not a novel cryptographic trick. Just a permission that shouldn't have been open.
Duelbits: a repeat customer
Crypto casino Duelbits went offline the same day after PeckShield flagged roughly $4.3 million in suspicious outflows across Ethereum and BNB Chain: 836 ETH (~$2.23M), 1.146 million USDT, 209 BNB (~$160.7K), 96,805 USDC, 12.4 billion SHIB (~$70.2K), and 31,515 DAI. The attacker routed the haul through deBridge and Relay's Router V3, then consolidated most of it into roughly 1,588 ETH while leaving the DAI largely untouched.
Duelbits hasn't disclosed how access was obtained, and it's still unclear whether player balances were affected — only that hot wallets were hit. Scam Sniffer's tally came in a touch lower, around $4.2 million, but the firm flagged that Tron wallets were drained too; later on-chain activity involving Bitcoin and Solana pushed some estimates toward $5.9 million before things settled down. The working theory is a leaked private key, not a contract bug.
This isn't Duelbits' first time here. The casino lost $4.64 million in February 2024 in an incident CertiK attributed to a compromised private key, with the attacker exploiting a double-counting flaw in a token contract's balance logic. Two major hacks, roughly 18 months apart, both tracing back to key or access failures rather than some exotic new attack vector. That pattern alone says something about how much work hot-wallet operators still have ahead of them.
The bigger picture
Zoom out and the timing lines up with a trend security firms have been flagging all year. Immunefi counted 207 hack incidents in the first half of 2026, a record, for roughly $972 million lost. CertiK's tally for the same stretch landed closer to $1.32 billion. The gap between those two numbers matters less than what both firms agree on: attackers have largely moved up the stack. Smart-contract bugs are harder to find now, thanks to continuous audits and bug bounty programs, so the money has followed the path of least resistance into infrastructure, leaked keys, misconfigured bridges, and privileged access that was never locked down properly.
Payy and Duelbits, hit hours apart by two different methods, both land squarely in that bucket. Neither company has published a full post-mortem yet, and the figures on both incidents could still move as investigators keep tracing the funds.

100 mücevhere kadar %5 para yatırma bonusu

Para yatırma ve çekme işlemlerinde %0 ücret.


11 Para Yatırma Bonusu + FreeSpin
EKSTRA %10 PARA YATIRMA BONUSU + ÜCRETSIZ 2 ÇARK DÖNDÜRME
Ücretsiz Kasa ve %100 Hoş Geldin Bonusu
5 Ücretsiz Kılıf, Günlük Ücretsiz ve Bonus

3 ücretsiz kasa ve tüm nakit para yatırma işlemlerine %5 bonus eklenir.

Depozitoya +%5

Yorum