Duelbits Crypto Hack Drains $7M as Casino Goes Offline

Written by

in

Key Highlights

  • Crypto casino Duelbits suffered a ~$7 million exploit across four blockchain networks, with hot wallets on BNB Chain, Ethereum, Tron, and Bitcoin drained by attackers.
  • Stolen assets—including 836 ETH, 593,000 USDT, 97,000 USDC, 31,500 DAI, 12.4 billion SHIB, and 8.1 BTC—were rapidly swapped into Ether and consolidated into a single address holding roughly 2,234 ETH (~$6 million).
  • Co-founder Joe confirmed the breach and stated the platform will remain offline until the investigation concludes and hot wallets are replenished; users are warned against phishing links circulating during the outage.

Multi-Chain Hot Wallet Compromise Drains Millions

Blockchain security firm Scam Sniffer—described in the source as “a company that specializes in blockchain security research”—first flagged a string of unusual transfers from Duelbits wallets on BNB Chain, Ethereum, and Tron. A subsequent detection revealed a loss of 8.1 BTC from the platform’s Bitcoin wallet. The affected wallets were identified as hot wallets: online accounts where a platform holds sufficient cryptocurrency to process client deposits and withdrawals quickly. While convenient for transaction speed, hot wallets carry elevated risk if credentials are compromised.

Co-Founder Confirms Breach, Investigation Underway

Duelbits co-founder Joe publicly acknowledged the incident, writing:

Confirming a ~$7M hack. Still investigating exactly what happened and how.

Joe added that the casino would remain offline until the investigation is complete and the company has replenished its hot wallets. As of publication, there has been no independent verification of the safety of user funds, and Duelbits has not disclosed how the attackers gained system access or provided a timeline for reopening withdrawals.

Stolen Funds Converted to Ether, Complicating Recovery

The attacker’s haul included 836 ETH, approximately 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB. Due to the speed and scale of the withdrawals, Scam Sniffer suspects a private key compromise—meaning the master credentials controlling the wallets were obtained, allowing transfers without exploiting the underlying blockchains. Duelbits has not confirmed this theory.

Most of the stolen tokens were swiftly exchanged for Ether and consolidated into a single address holding about 2,234 ETH, valued at roughly $6 million at the time of tracing. The funds had not moved onward. This conversion to Ether significantly complicates potential recovery: the issuers of USDT and USDC can freeze those assets, but Ether has no central issuer capable of freezing or reversing transactions.

Why This Matters

The Duelbits hack underscores the persistent vulnerability of centralized hot-wallet infrastructure in the crypto-gambling sector. When platforms concentrate liquidity in online wallets for operational speed, a single private-key breach can expose millions across multiple chains simultaneously. The rapid conversion of stablecoins and altcoins into Ether—an asset without a freeze mechanism—demonstrates how attackers structure exits to evade recovery efforts. For users, the incident highlights the importance of verifying platform solvency claims independently and remaining vigilant against phishing campaigns that surge during service outages.

Frequently Asked Questions

Which blockchains and assets were affected in the Duelbits hack?

The exploit hit hot wallets on BNB Chain, Ethereum, Tron, and Bitcoin. Stolen assets included 836 ETH, ~593,000 USDT, 97,000 USDC, 31,500 DAI, 12.4 billion SHIB, and 8.1 BTC.

Can the stolen funds be frozen or recovered?

The attacker converted most tokens into Ether and consolidated them in one address. While USDT and USDC issuers can freeze those specific tokens, Ether cannot be frozen because it has no central issuer. Recovery prospects therefore depend on law-enforcement action or the attacker’s future mistakes.

Is Duelbits currently operational, and what should users do?

Duelbits has taken its site offline and has not announced a reopening date. Co-founder Joe stated the platform will stay down until the investigation finishes and hot wallets are replenished. Users should avoid any “refund” or “recovery” links circulating during the outage, as these are likely phishing attempts designed to steal wallet credentials.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *