Tag: Private key compromise

  • Crypto Casino Duelbits Goes Offline After $7 Million Hot Wallet Hack

    Crypto Casino Duelbits Goes Offline After $7 Million Hot Wallet Hack

    Key Highlights

    • Crypto gambling platform Duelbits suffered a $7 million hot wallet exploit on Thursday, prompting the site to go offline while co-founder Joe confirmed “user funds are safe.”
    • Blockchain security firm Scam Sniffer identified a suspected private key compromise affecting wallets on Ethereum, BNB Chain, Tron, and Bitcoin, with 8.1 BTC also stolen.
    • The attack mirrors the 2023 Stake.com breach, where hackers stole $40 million using the same private key compromise method.

    Duelbits Takes Platform Offline After $7 Million Hot Wallet Drain

    Crypto gambling platform Duelbits went offline on Thursday after attackers drained approximately $7 million from its hot wallets across multiple blockchains. The incident was first flagged by blockchain security firm Scam Sniffer, which reported that Duelbits hot wallets on Ethereum, BNB Chain, and Tron had sent funds to newly created addresses in what appeared to be a private key compromise. The firm later confirmed the company’s Bitcoin hot wallet also lost 8.1 BTC in the attack.

    Co-Founder Confirms Breach, Assures User Funds Secure

    Duelbits co-founder Joe addressed the incident on X, stating: “Confirming a ~$7M hack. Still investigating exactly what happened and how,” adding that “user funds are safe.” He indicated the platform would remain offline until the investigation concludes and its hot wallets are refilled. The direct acknowledgment from leadership came as on-chain data continued to reveal the full scope of the asset movements.

    On-Chain Analysis Reveals Multi-Chain Asset Losses

    Etherscan data shows the Ethereum wallet labeled as a Duelbits hot wallet transferred 836 ETH, approximately 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB to the attacker within minutes. The compromised Ethereum wallet now holds less than $25 in ether. Scam Sniffer’s analysis indicates the simultaneous compromise across Ethereum, BNB Chain, Tron, and Bitcoin networks strongly points to a private key breach rather than a smart contract vulnerability.

    Attack Method Mirrors 2023 Stake.com Breach

    The suspected private key compromise mirrors the methodology used in the 2023 attack on Stake.com, the largest crypto casino by volume, where hackers made off with $40 million. That incident, also attributed to a private key compromise, raised significant concerns about key management practices across the crypto gambling sector. The recurrence of this attack vector suggests persistent operational security challenges for platforms managing large hot wallet balances.

    Why This Matters

    The Duelbits hack underscores the ongoing vulnerability of centralized hot wallet infrastructure in the crypto gambling industry. Despite high-profile incidents like the Stake.com breach, platforms continue to maintain substantial assets in internet-connected wallets secured by single points of failure. The multi-chain nature of this exploit—hitting Ethereum, BNB Chain, Tron, and Bitcoin simultaneously—demonstrates how a single private key compromise can cascade across an operator’s entire treasury. For users, the incident reinforces the importance of platform solvency transparency and the risks inherent in custodial gambling platforms. Regulators and industry watchdogs will likely scrutinize whether Duelbits’ claim that “user funds are safe” holds up during the investigation and whether the platform maintains sufficient cold storage reserves to cover the hot wallet losses without impacting customer balances.

    Frequently Asked Questions

    How much was stolen in the Duelbits hack?

    Approximately $7 million was drained from Duelbits hot wallets across Ethereum, BNB Chain, and Tron, plus an additional 8.1 BTC from the platform’s Bitcoin hot wallet.

    What caused the Duelbits security breach?

    Blockchain security firm Scam Sniffer identified a suspected private key compromise as the attack vector, noting that wallets across multiple chains sent funds to newly created addresses simultaneously.

    Is Duelbits currently operational?

    No, Duelbits has taken its platform offline. Co-founder Joe stated the site will remain offline until the investigation is finished and hot wallets are refilled.

  • Fetch.ai and NuNet Lose $2 Million in Private Key Compromise

    Fetch.ai and NuNet Lose $2 Million in Private Key Compromise

    Key Highlights

    • A single attacker exploited compromised privileged credentials to drain $1.53 million in $FET from Fetch.ai and mint 408.5 million unauthorized NTX tokens worth $462,730 from NuNet, totaling approximately $2.01 million.
    • Security firms PeckShield, Blockaid, and SlowMist linked both incidents to the same wallet, identifying a critical failure in key management where a single ECDSA signature from an externally owned account authorized the TokenConversionManagerV3 contract without limit checks or on-chain proof verification.
    • NTX collapsed nearly 95% to an all-time low of $0.00004075 due to massive supply inflation, while $FET remained relatively stable because the attack removed existing tokens rather than creating new ones.

    Coordinated Infrastructure Exploit Targets Fetch.ai and NuNet

    An attacker compromised privileged signing credentials to breach infrastructure shared by Fetch.ai and NuNet, two projects within the broader Artificial Superintelligence Alliance ecosystem, extracting approximately $2.01 million in a coordinated exploit detected on September 19, 2026. Blockchain security firms PeckShield and Blockaid independently traced both incidents to the same attacker wallet cluster, revealing a cascade failure in operational security that spanned connected systems despite the underlying token contracts themselves remaining uncompromised.

    According to PeckShield, the exploiter siphoned 8.7 million $FET valued at $1.53 million from a Fetch.ai converter contract, while simultaneously receiving an unauthorized mint of 408.5 million NTX tokens worth approximately $462,730 from the NuNet deployer account. Blockaid’s real-time monitoring confirmed approximately $1.56 million in $FET drained from the converter alongside roughly $452,000 in newly minted NTX, bringing the total observed value to $2.01 million while the attack was still ongoing. NuNet, described by CoinMarketCap as the second spin-off from SingularityNET, operates within the same AI-crypto ecosystem as Fetch.ai, amplifying the systemic implications of the shared credential compromise.

    Single Signature Authorization Failure Identified as Root Cause

    SlowMist’s technical analysis pinpointed the structural vulnerability: the TokenConversionManagerV3 contract relied solely on an ECDSA signature from a single externally owned account to authorize the conversionIn() function that drained the $FET reserves. The contract lacked a checkLimits(amount) control mechanism and did not verify the presence of burn or lock proofs on-chain. This design meant that once the authorizer key was compromised, a legitimate signature alone was sufficient to empty the converter’s entire $FET balance without additional safeguards.

    Fetch.ai’s preliminary analysis concluded that the signing key had likely been compromised, while on-chain evidence suggests the NuNet minting key may have suffered a similar breach. The projects responded collaboratively: Fetch.ai confirmed it worked with SingularityNET to deactivate affected wallets and contracts, stating that no Fetch.ai contracts remained at risk and that AGIX-to-$FET conversions had been paused as a precaution. An on-chain analysis tracing the attack from the compromised signing key to the attacker’s cash-out wallets has been published on ASI:One, though Fetch.ai emphasized this is not the final report.

    Divergent Market Impacts Highlight Supply Dynamics

    The two tokens exhibited starkly different price responses driven by the distinct mechanics of each exploit. The $FET hack removed previously issued tokens from circulation, while the NTX hack generated hundreds of millions of unauthorized tokens, fundamentally compromising supply integrity and creating intense selling pressure. CoinMarketCap data shows NTX trading around $0.000066, down nearly 95% within 24 hours after hitting an all-time low of $0.00004075 on September 20. In contrast, $FET avoided a comparable catastrophe because the attack reduced rather than inflated its circulating supply.

    Why This Matters

    While the $2 million direct loss appears modest against the estimated $2.85 trillion cryptocurrency market capitalization, the attack methodology aligns with a dominant and escalating industry threat vector. TRM Labs recorded 207 hacks totaling $972 million in losses during the first half of 2026, with infrastructure and operational compromises accounting for only 15% of incidents but approximately 76% of stolen funds. CoinGecko’s 2026 security report reinforces this pattern, documenting over $1.8 billion in losses from infrastructure and supply-chain breaches between January 2025 and July 2026, with private-key compromise persisting as a primary failure point. A parallel case emerged in June 2026 when Humanity Protocol disclosed that exposed private keys contributed to losses up to $31 million, sending its H token down as much as 90%. The Fetch.ai and NuNet incident underscores how weaknesses in key management can cascade across interconnected protocols, even when smart contracts themselves are not directly exploited.

    Frequently Asked Questions

    How did the attacker gain access to both Fetch.ai and NuNet systems?
    Security firms linked both exploits to the same attacker wallet. Fetch.ai’s analysis indicates the signing key for the TokenConversionManagerV3 contract was compromised, allowing unauthorized conversionIn() calls. On-chain evidence suggests the NuNet minting key may have been similarly compromised, enabling the unauthorized NTX mint from the deployer account.
    Why did NTX crash 95% while $FET remained stable?
    The $FET exploit drained existing tokens from a converter contract, reducing circulating supply. The NTX exploit minted 408.5 million new unauthorized tokens, massively inflating supply and destroying tokenomics. This supply shock created overwhelming sell pressure that crashed NTX from ~$0.000066 to an all-time low of $0.00004075.
    What steps have Fetch.ai and NuNet taken to contain the damage?
    Fetch.ai deactivated affected wallets and contracts in coordination with SingularityNET, paused AGIX-to-$FET conversions as a precaution, and stated no Fetch.ai contracts remain at risk. An on-chain analysis is available on ASI:One tracing the attack flow. NuNet’s specific remediation steps for the unauthorized NTX supply have not been detailed in the current reports.