DeFi Exploits September 2026
Detailed overview of major DeFi exploits in September 2026, including Payy, Duelbits, and Meter security incidents and their user impacts.

DeFi Exploits in September 2026: Payy, Duelbits and Meter Compared
The quick list
- Most urgent balance check: Payy Network, for users with USDC deposited through its bridge or Payy Wallet, after a single transaction drained about $1.83 million and the network paused operations. [1]
- Most severe service interruption: Duelbits, for casino customers needing to verify whether their balances remain accessible, after a multi-chain hot-wallet breach prompted the platform to go offline. [3]
- Most direct market-price shock: Meter Protocol, for MTRG holders and bridge users exposed to thin liquidity, after unbacked token issuance drove a reported 71.7% price decline. [4]
- No confirmed card impact: Crypto payment cards linked indirectly to these services, for users separating card custody risk from protocol risk, because reporting has not established a connection between the incidents and card functionality.
The practical decision is not which exploited platform is “best”. It is whether a user’s funds sat in a bridge, a custodial hot wallet, a volatile protocol token, or an entirely separate card programme.
That distinction determines the immediate cost. The reported loss figures are not product prices or a measure of guaranteed customer losses. They are estimates of assets removed from wallets or created without backing, and recovery remains uncertain.
The second risk is disclosure. A paused network may preserve evidence but leave users unable to withdraw. A platform assertion that balances are safe is not the same as an independently verified reserve, an insurance policy, or a timetable for restored access.
| Incident / service | Reported cost of incident | Apparent attack path | Immediate user impact | Market impact | Public disclosure gap |
|---|---|---|---|---|---|
| Payy Network | About $1.83 million USDC [[1]](https://itokenly.com/hacks/payy-network-bridge?utm_source=openai "Payy Network (Ethereum bridge contract) hack — September 2026 | iTokenly — all about crypto") | Ethereum bridge drain, root cause undisclosed | Operations paused, bridge deposit exposure | No reported protocol-token crash |
| Duelbits | About $4.9 million to $6 million by investigator estimates, versus approximately $7 million disclosed by co-founder [[3]](https://www.gate.com/en-us/news/detail/duelbits-suffers-49m-6m-suspected-private-key-compromise-across-five-17880997?utm_source=openai "Duelbits Suffers $4.9M-$6M Suspected Private Key Compromise Across Five Blockchains on September 24 | Gate US") | Suspected private-key compromise across several chains | Site taken offline while wallets are replenished and investigated | No directly reported platform-token event |
| Meter Protocol | About $2.3 million [4] | Unbacked wrapped MTRG minted and sold | Mainnet and bridge paused, recovery method undecided | MTRG reportedly fell 71.7%, from $0.0099 to $0.0027 [4] | No detailed public remediation or liquidity plan |
| Crypto card programmes | No confirmed direct loss tied to these incidents | No established attack linkage | Depends on the separate card issuer and custody arrangement | None confirmed | Reporting does not establish a card-security impact |
What happened, and what it cost
The three September 24 incidents show why “DeFi exploit” is too broad a label for evaluating user risk. Payy Network, Duelbits and Meter each involved blockchain assets, but the custody model, operational consequences and likely paths to recovery were different.
Payy Network, a rollup offering on-chain payroll and treasury functions, lost about $1.83 million in USDC when its Ethereum bridge was drained in a transaction reported at roughly 04:21 UTC. The project subsequently paused operations. [1]
The immediate exposure at Payy was bridge-related. Payy said the funds represented users’ non-custodial deposits to Payy Network or Payy Wallet, which matters because non-custodial design does not eliminate smart-contract, bridge or operational risk.
The root cause remains undisclosed. There is no confirmed public explanation of whether the loss resulted from a contract flaw, compromised credentials, validator issue or another failure. That uncertainty makes claims about remediation premature. [1]
Duelbits, a crypto casino and sports-betting platform, faced a different problem. Blockchain watchers identified suspicious outflows from hot wallets across Ethereum, BNB Chain, Tron, Bitcoin and Solana, consistent with a suspected private-key compromise. [3]
The loss estimate has varied with the measurement method. Blockchain investigators initially put the loss in a range of roughly $4.9 million to $6 million, while a Duelbits co-founder later described the incident as an approximately $7 million hack. [3]
Those figures are not necessarily contradictory. A moving estimate can reflect asset-price changes, additional wallets discovered after the initial alert, or differences between confirmed transfers and a company’s broader internal accounting. Neither figure establishes final customer losses.
Duelbits took its website offline while investigating and refilling hot wallets. Its security materials describe account tools including two-factor authentication, while the platform also says it uses cold storage for player funds and runs a bug bounty programme. [5]
Those controls do not remove the central issue in this event. A compromise of a wallet-management private key can bypass protections designed for customer logins, and moving some funds to cold storage does not explain how much remained exposed in operational hot wallets.
Meter Protocol’s incident was structurally different again. Rather than draining a pool of existing deposited assets, an attacker reportedly exploited a block-validation flaw to mint unbacked wrapped MTRG on BNB Chain, then sold part of the newly created supply into PancakeSwap. [4]
That design created a problem beyond the initial $2.3 million estimate. Selling unbacked tokens into available liquidity can impair the market price of the asset held by existing users, even those whose individual wallets were never directly accessed.
The reported result was a 71.7% drop in MTRG, from about $0.0099 to $0.0027. The price move makes Meter the clearest example of market risk among the three incidents, rather than solely an accounting loss at a service operator. [4]
Why the differences matter for user balances
Payy users face the least transparent situation. The reported drain was smaller than the Duelbits breach and the Meter mint, but the absence of a disclosed cause leaves users unable to assess whether the relevant bridge architecture has been fixed.
There is also no publicly available post-incident information establishing Payy’s security arrangements, reserve treatment or insurance coverage. Users should not infer protection merely because deposits were described as non-custodial or because operations were paused. [1]
Duelbits users face a custodial-access problem. The operator said user funds were safe, but the platform remained offline while it investigated the intrusion and replenished hot wallets. Access and solvency are separate questions during that period.
The platform’s Curacao licence is also not a universal customer-protection framework. US oversight of crypto gambling remains fragmented by state, and the August Ninth Circuit decision affirming state authority over online sports-betting regulation may shape future enforcement without creating a new nationwide regime.
Meter users face a protocol and market-structure problem. The team said it had preserved the chain state, but said the recovery method was still to be decided. That leaves open questions about token supply, liquidity restoration and the treatment of affected bridging activity.
The most important trade-off is therefore not between platforms’ advertised features. It is between different failure modes: bridge-contract exposure at Payy, operational-key exposure at Duelbits, and token-supply plus liquidity exposure at Meter.
Crypto cards: what has not been shown
Crypto cards are relevant mainly because users often treat card balances, exchange balances and DeFi balances as interchangeable. They are not necessarily interchangeable. A card can be funded by a separate issuer, custodian, stablecoin account or exchange wallet.
As of September 25, there is no confirmed evidence that the Payy, Duelbits or Meter incidents affected the usability or security of crypto payment cards. Reporting on the events concerns bridge assets, hot wallets, minted tokens and decentralised-exchange liquidity, not card processors or card programmes.
That does not prove every card arrangement is insulated. It means no direct linkage has been publicly established. The relevant question is where the card issuer holds settlement funds and whether the affected service was the issuer, custodian or merely a funding source.
Users with cards funded from an affected platform may encounter practical disruption if deposits, withdrawals or conversions are paused. That is an access issue, however, not evidence that card credentials, payment rails or card balances were themselves compromised.
Reading the loss figures cautiously
September’s incidents occurred against a market where bitcoin traded around $84,000 and broader risk appetite remained sensitive to bond yields and energy prices. That setting can complicate dollar-loss estimates, especially when stolen assets are converted into ether or sold across chains.
It can also encourage unsupported recovery forecasts. A bridge exploit is not automatically made whole because a project pauses operations. A casino’s statement that funds are safe is not an audited balance sheet. A token’s sharp decline is not proof of permanent impairment either.
Meter’s fall is the clearest case where price action should not be treated as a forecast. The reported 71.7% decline measures an immediate liquidity and confidence shock after unbacked supply hit the market. It does not establish a future value. [4]
Similarly, neither the Payy loss total nor the Duelbits estimate proves the final cost to individual customers. The decisive facts would be wallet reconciliation, reserve disclosures, recovery transactions, reimbursement terms and, where applicable, independently verifiable on-chain evidence.
Who each option suits
Payy Network suits users assessing bridge-specific exposure, particularly those who deposited USDC through the affected Ethereum bridge or relied on Payy Wallet functions. Its reported cost was about $1.83 million, but the key issue is unresolved causation and the lack of disclosed insurance or remediation detail. [1]
Duelbits suits users assessing custodial-platform exposure, especially customers who need to distinguish account-level security from the operator’s wallet-security practices. Its estimated cost ranges from $4.9 million to $7 million, and the practical issue is restored access plus substantiation of the company’s assurance on user funds. [3]
Meter Protocol suits users assessing token-market and bridge exposure, including holders of MTRG and participants dependent on its bridge. The $2.3 million incident mattered because minted, unbacked supply was sold into liquidity, producing the reported 71.7% price decline. [4]
Crypto card users suit a separate category of review, not an automatic inclusion in the exploit totals. No confirmed reporting ties these incidents to card compromise, so the relevant assessment is the specific issuer’s custody, settlement and account-access arrangements rather than the headline loss at an unrelated protocol.
Frequently Asked Questions
What were the major DeFi exploits in September 2026?
The major DeFi exploits on September 24, 2026, involved Payy Network, Duelbits, and Meter Protocol. Payy Network’s Ethereum bridge was drained of about $1.83 million USDC, Duelbits suffered a multi-chain hot-wallet breach with losses estimated between $4.9 million and $7 million, and Meter Protocol experienced a $2.3 million unbacked token mint that caused a sharp price drop in its MTRG token.
How did the Payy Network exploit affect users?
Users who had USDC deposited through Payy Network’s Ethereum bridge were directly affected, as about $1.83 million was drained in a single transaction. The network paused operations following the exploit, leaving bridge deposits exposed and users unable to withdraw funds. The root cause of the exploit remains undisclosed, and there is no public information on insurance or compensation.
What caused the Duelbits hot wallet breach in September 2026?
The Duelbits breach was caused by a suspected private-key compromise affecting hot wallets across multiple blockchains. This led to an estimated loss of $4.9 million to $7 million. As a result, Duelbits took its platform offline to investigate and replenish wallets. No public insurance or compensation mechanism has been disclosed for affected customers.
What was the impact of the Meter Protocol token exploit?
The Meter Protocol exploit involved minting about $2.3 million of unbacked wrapped MTRG tokens, which attackers sold on PancakeSwap, causing the MTRG token price to fall approximately 71.7%, from $0.0099 to $0.0027. The Meter mainnet and bridge were paused, and users were advised to halt activity. No detailed public plan for remediation or liquidity restoration has been announced.
Did the September 2026 DeFi exploits affect crypto payment cards?
There is no confirmed evidence that the September 2026 DeFi exploits disrupted crypto payment card programs or compromised card security. Reports have not established any direct linkage between these incidents and crypto card usability or safety, so cardholders should consider risks separately based on their card issuer and custody arrangements.
How we researched this
This article was assembled from 3 published articles, 5 cited references.
Nothing here is based on hands-on testing. Where a figure or finding appears, it belongs to the source cited beside it, and the writing says so rather than implying otherwise. Every source is listed below so you can check it.
Sources
Live updates: Bitcoin steadies near $84,000 as the bond selloff pauses — CoinDesk
DeFi hack attack: Three exploits snatch $11M in a single day — Protos
Crypto casino Duelbits goes offline after $7 million hot wallet hack — CoinDesk
Payy Network (Ethereum bridge contract) hack — September 2026 | iTokenly — all about crypto
DeFi Price-Manipulation Exploits Surge To Record High In 2026
Related Articles

Liquid Network Bitcoin Theft
Explore the Liquid Network Bitcoin theft, partial recovery, and the security flaws behind the $320M exploit affecting federated sidechains.

Tectonic Crypto Exploit
Explore the Tectonic crypto exploit, its impact on Cronos, and how collateral manipulation led to a $75M loss in DeFi lending protocols.

Crypto Security Incidents and Protocol Responses Explained
Explore recent crypto security incidents and how protocols respond with halts, patches, and recovery strategies to limit losses.

Trezor Data Breach Expansion: Over 80,000 Customers Affected
Learn about the Trezor data breach expansion affecting 80,000+ customers and how to protect yourself from phishing risks linked to exposed data.