Duelbits Confirms $7 Million Hot-Wallet Hack, forcing Systems offline
Duelbits confirmed a roughly $7 million hot-wallet theft and took the crypto casino offline.
Crypto casino Duelbits confirmed attackers drained about $7 million from hot wallets on Ethereum, BNB Chain, Tron, and Bitcoin, and took the site offline. Scam Sniffer first reported about $4.2 million in outflows; investigators later added 8.1 BTC, and most stolen assets were consolidated into roughly 2,234 ETH. Ethereum transfers included 836 ETH, about 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB. Co-founder Joe said user balances are safe and a statement is due within 24 hours, while engineers rebuild deposit and withdrawal servers; private-key compromise is suspected but not confirmed.
- About $7 million left Duelbits hot wallets across several chains.
- Scam Sniffer initially reported roughly $4.2 million in abnormal outflows.
- Stolen assets were largely converted to Ether and consolidated.
- Duelbits says user funds are safe and is rebuilding withdrawal systems.
- Private-key exposure is suspected but not officially confirmed.
Full article594 words · extracted from cybersecuritynews.com · click to collapse
Crypto casino Duelbits has confirmed a cybersecurity breach that drained approximately $7 million from its hot wallets, forcing the platform offline while investigators establish the attack’s root cause.
Co-founder Joe disclosed the incident on X, assured customers that user funds remain safe, and said operations would resume after the investigation and wallet replenishment are completed.
— Joe (@DuelbitsJoe) September 24, 2026Confirming a ~$7M hack. Still investigating exactly what happened and how.
Until we have clarity, Duelbits stays offline. User funds are safe.
Next steps: finish the investigation, re-top hot wallets, and bring Duelbits back online, launch Duelbits 2.0.
I'll keep posting… https://t.co/V4Zl4St31I
The incident surfaced through suspicious transactions spanning several blockchains. Blockchain security firm Scam Sniffer initially reported about $4.2 million in abnormal outflows from Duelbits hot wallets on Ethereum, BNB Chain, and Tron to newly created addresses.
The firm assessed the activity as a suspected private-key compromise. Investigators later identified 8.1 BTC leaving the company’s Bitcoin hot wallet, increasing reported losses to approximately $7 million.
On Ethereum, the affected wallet transferred 836 ETH, roughly 593,000 USDT, 97,000 USDC, 31,500 DAI and 12.4 billion SHIB within minutes. Additional outflows included 209 BNB and 192,000 TRX. Most stolen assets were converted into Ether and consolidated into a single address holding around 2,234 ETH, valued at approximately $6 million when traced.
Although the transaction pattern indicates unauthorized control of wallet-signing capabilities, Duelbits has not released a technical root-cause analysis. The suspected private-key exposure therefore remains a security researchers’ assessment, not a confirmed conclusion.
If signing credentials were compromised, attackers could authorize valid-looking transfers without exploiting a smart contract, making immediate credential rotation and wallet isolation critical.
In updates, Joe said Duelbits had identified what happened and promised an official statement within 24 hours. He estimated that the website could return within 15 hours, while cautioning that engineers were rebuilding the platform’s deposit and withdrawal servers to ensure the infrastructure was secure. The company apologized for the disruption and said the work is intended to prevent a repeat incident.
— Joe (@DuelbitsJoe) September 24, 2026We’ve identified what happened.
An official statement will follow within 24 hours.
User funds are safe. Duelbits will be back stronger than ever. Ignore the FUD.
Duelbits 2.0 is close.
The site should be back up within ~15 hours.
We’re rebuilding our deposit and withdrawal… https://t.co/Whd44cJSPV
Duelbits’ recovery plan includes completing the investigation, replenishing hot wallets, restoring services and launching Duelbits 2.0. Keeping the platform offline reduces exposure while engineers can rotate keys, review privileged access, reconcile balances and validate transaction systems.
However, the company has not yet explained the access vector, the wallet-custody architecture involved, or whether incident-response specialists and exchanges are assisting with asset recovery.
Customers should use only Duelbits’ official website and verified social accounts for updates. They should avoid unsolicited refund or recovery messages and never share seed phrases, passwords, or authentication codes, as criminals exploit high-profile cryptocurrency incidents by impersonating others and using phishing.
Duelbits maintains that customer balances are protected and says the platform will return stronger. Nevertheless, the incident remains active until its statement documents the confirmed root cause, affected systems, stolen assets, and safeguards.
Independent verification of resumed deposits and withdrawals will be essential for rebuilding trust after the $7 million Duelbits hack.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.