Duelbits Hot Wallet Hack Drains $7 Million, Forces Platform Offline
Duelbits confirmed a hot-wallet breach that drained about $7 million and took the casino offline.
Crypto casino Duelbits confirmed unauthorized transfers that drained about $7 million from hot wallets across Ethereum, BNB Chain, Tron, and Bitcoin. Reported movements included 836 ETH, stablecoins, SHIB, 209 BNB, 192,000 TRX, and 8.1 BTC, with much of the value consolidated into about 2,234 ETH. Co-founder Joe said user funds are safe and the platform will stay offline until the investigation is finished and hot wallets are replenished. Duelbits has not confirmed the root cause; a private-key compromise is only an external assessment.
- Duelbits confirmed roughly $7 million drained from its hot wallets.
- Outflows hit Ethereum, BNB Chain, Tron, and Bitcoin wallets.
- Scam Sniffer first reported about $4.2 million in abnormal transfers.
- The platform stays offline until the investigation and wallet refill finish.
- Private-key compromise remains an unconfirmed external theory.
Full article633 words · extracted from gbhackers.com · click to collapse
Crypto casino Duelbits has confirmed a cybersecurity breach that drained approximately $7 million from its hot wallets. In response, the company has taken its platform offline while it investigates the incident.
Co-founder Joe said they are still determining “exactly what happened and how,” while assuring customers their funds are safe.
Multi-Chain Wallet Drain
The incident came to light after blockchain security researchers identified suspicious transfers from wallets associated with Duelbits. Scam Sniffer initially reported around $4.2 million in abnormal outflows involving Ethereum, BNB Chain, and Tron wallets, with funds routed to newly created addresses, an indication that suggested a possible private key compromise.
Further analysis revealed an additional 8.1 BTC removed from a Duelbits Bitcoin hot wallet, bringing the total reported losses to about $7 million. This breach affected wallet infrastructure across at least four blockchain networks: Ethereum, BNB Chain, Tron, and Bitcoin.
On Ethereum, the affected wallet reportedly sent 836 ETH, about 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB to addresses controlled by the attacker within minutes. Additional reported transfers included 209 BNB and 192,000 TRX.
The attacker quickly converted a significant portion of the stolen tokens into Ether. Blockchain investigators traced much of the stolen value to a single address holding about 2,234 ETH, worth close to $6 million at the time of reporting.
The rapid multi-asset conversion and consolidation complicate incident response efforts, particularly when attackers move assets across chains and swap tokens before operators can freeze or blocklist associated addresses. Nevertheless, wallet tracing can still provide exchanges, analytics firms, and law enforcement with indicators that may help identify future cash-out attempts.
Duelbits has not released wallet addresses, technical indicators, a timeline of unauthorized access, or information about the custody architecture involved. As a result, the theory regarding a private key compromise remains an external assessment rather than a confirmed cause.
Joe confirmed that the company will keep Duelbits offline until its investigation is complete and the hot wallets are replenished. The recovery plan also includes restoring the platform and launching “Duelbits 2.0.”
— Joe (@DuelbitsJoe) September 24, 2026Confirming a ~$7M hack. Still investigating exactly what happened and how.
Until we have clarity, Duelbits stays offline. User funds are safe.
Next steps: finish the investigation, re-top hot wallets, and bring Duelbits back online, launch Duelbits 2.0.
I'll keep posting… https://t.co/V4Zl4St31I
Taking the service offline is a wise containment measure. If attackers gained access to wallet-signing credentials or privileged operational systems, continuing availability could expose remaining assets, deposits, withdrawals, or administrative infrastructure to additional risk.
A comprehensive recovery should include:
- Rotating all hot-wallet private keys and API credentials.
- Isolating compromised signing environments and reviewing access logs.
- Reconciling customer liabilities and platform wallet balances.
- Reviewing privileged-account access, endpoint security, and cloud controls.
- Moving assets into segregated, multi-signature, or hardware-backed custody systems.
- Validating deposit and withdrawal infrastructure before returning services to production.
Duelbits assures users that their balances remain protected, but users should stay vigilant against phishing attempts that may exploit the outage. Threat actors often impersonate exchanges, casinos, support staff, or recovery services following public cryptocurrency thefts.
Customers should rely solely on the official Duelbits website and verified social media accounts. They should never share seed phrases, passwords, private keys, one-time codes, or recovery information with anyone claiming to offer refunds or account restoration.
The incident remains under investigation. The most critical upcoming disclosure will be Duelbits’ confirmed root cause analysis, which should include details on the compromised systems, affected asset pools, recovery actions, and safeguards implemented before resuming deposits and withdrawals.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.