Skip to content
Est. MMXXVIVol. VI · № 343RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 340Private Key Compromise

Duelbits Hot-Wallet Compromise

Attackers drained about $7 million from crypto casino Duelbits's hot wallets across five chains in a suspected private-key compromise, forcing the platform offline.

Date
Victim
Duelbits
Status
Funds Stolen

On September 24, 2026, Duelbits — a crypto casino and sports-betting platform — was drained of roughly $7 million from its hot wallets in what investigators described as a suspected private-key compromise, forcing the site offline.

What happened

On-chain monitor Scam Sniffer first flagged a wave of unauthorized outflows spanning Ethereum, BNB Chain, Tron, Bitcoin, and Solana. Within minutes, attackers moved 836 ETH, about 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB out of Duelbits's Ethereum-side hot wallets, plus roughly 8.1 BTC from a Bitcoin hot wallet. Once outflows from the Bitcoin and Solana wallets were tallied, total losses climbed toward $7 million. The clean, simultaneous sweep across unrelated chains pointed to leaked or stolen private keys rather than a single smart-contract bug. Most of the stolen assets were then swapped to ether and consolidated into one address holding about 2,234 ETH — worth roughly $6 million — which sat unmoved afterward.

Aftermath

Duelbits took its site offline and co-founder "Joe" confirmed the roughly $7 million loss on X, saying services were suspended until the investigation concluded and the hot wallet was replenished, while insisting user balances were safe. As of late September 2026 the stolen funds, though consolidated and still visible on-chain, had not been recovered, so the status here is stolen.

Why it matters

Hot wallets are a permanent trade-off: the same keys that let a platform settle bets instantly can drain it instantly if they leak. The near-simultaneous multi-chain sweep is the signature of key compromise, echoing the same-week Bitget backend breach, where spoofed authorizations — not a code flaw — moved the money. Custodial operators need hardware-backed key isolation, withdrawal rate limits, and anomaly detection that trips before a full sweep completes, not after.

Sources & on-chain evidence

  1. [01]coindesk.comhttps://www.coindesk.com/business/2026/09/24/crypto-casino-duelbits-goes-offline-after-usd7m-hot-wallet-hack
  2. [02]protos.comhttps://protos.com/defi-hack-attack-three-exploits-snatch-11m-in-a-single-day/
  3. [03]cryptobriefing.comhttps://cryptobriefing.com/duelbits-offline-7m-hot-wallet-hack/

Related filings