Crypto Casino Duelbits Goes Offline After $7 Million Hot Wallet Hack
Key Takeaways
- Attackers drained about $7 million from Duelbits’ hot wallets on Ethereum, BNB Chain, Tron and Bitcoin, in a pattern consistent with a private key compromise.
- The stolen assets, including ETH, USDT, USDC, DAI and SHIB, were swapped and consolidated into roughly 2,234 ETH worth about $6 million.
- The incident echoes the 2023 Stake hack, another private key compromise, and highlights the larger attack surface crypto casinos face from keeping funds readily liquid.
Crypto gambling platform Duelbits took its site offline Thursday after attackers drained roughly $7 million from its hot wallets in a suspected private key compromise. The company said user funds remain safe and that the platform will stay offline until its investigation concludes and affected wallets are refilled.
Confirmation Came Directly From the Co-Founder
Duelbits co-founder Joe confirmed the incident in a post on X, saying the company was still investigating exactly what happened.
“Confirming a ~$7M hack. Still investigating exactly what happened and how. User funds are safe.”
Duelbits separately said in a statement that it is investigating a security incident and took the platform offline as a precautionary measure while that investigation continues.
Wallets Across Four Blockchains Were Drained
Blockchain security firm Scam Sniffer first flagged the incident, reporting that Duelbits hot wallets on Ethereum, BNB Chain and Tron sent funds to newly created addresses in a pattern consistent with a compromised private key rather than a smart contract exploit.
Scam Sniffer later said the company’s Bitcoin hot wallet also lost 8.1 BTC, extending the breach across a fourth network.
A private key compromise, in which an attacker gains direct control of a wallet’s signing credentials rather th an exploiting a flaw in code, was also the method used against Stake, the largest crypto casino by trading volume, in a 2023 incident that resulted in $40 million in losses.
That distinction matters for how the crypto industry categorizes security incidents. A smart contract exploit typically points to a code vulnerability that can be patched and, in some cases, allows a project to trace exactly how funds were extracted.
A private key compromise instead points to a failure in how access credentials were generated, stored or protected. This is a category of breach that often proves harder to prevent through code audits alone since it depends on operational security practices rather than the correctness of deployed software.
On-Chain Data Traces the Stolen Funds
Etherscan data shows a wallet labeled as a Duelbits hot wallet sent 836 ETH, about 593,000 USDT, 97,000 USDC, 31,500 DAI and 12.4 billion SHIB to the attacker within minutes. That wallet’s Ethereum balance now stands at less than $25.
Most of the stolen assets have since been swapped into ether and consolidated into a single new address holding roughly 2,234 ETH, worth about $6 million as of publication. The funds had not moved onward as of this writing, meaning the attacker’s identity and next steps remain unknown.
The decision to swap a mix of stolen tokens, including stablecoins and smaller-cap assets like SHIB, into a single ether position is a common pattern among crypto hackers seeking to consolidate stolen funds into a more liquid, widely traded asset before attempting to launder or cash out the proceeds.
That consolidation also makes the stolen funds easier for outside investigators and blockchain analytics firms to track as a single address. This is possible even though it does not by itself prevent the attacker from eventually moving the funds through a mixer or cross-chain bridge.
Duelbits’ Position Among Tracked Crypto Casinos
Before the incident, DappRadar ranked Duelbits 17th among 43 tracked crypto casinos by on-chain deposits, with about $5.7 million recorded across its monitored wallets.
It is not clear from available data whether that figure reflects wallet balances before or after Thursday’s outflows. The ranking should be read as general market context rather than a precise measure of losses relative to the platform’s overall size.
The incident adds to a recurring pattern of hot wallet compromises affecting crypto gambling platforms specifically, a category of business that by its nature needs to keep meaningful liquidity readily accessible to process frequent user withdrawals. This is an operational requirement that can create a larger attack surface than platforms able to keep most funds in cold storage.