Duelbits Confirms $7 Million Hot-Wallet Hack, forcing Systems offline

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Crypto casino Duelbits has confirmed a cybersecurity breach that drained approximately $7 million from its hot wallets, forcing the platform offline while investigators establish the attack’s root cause.

Co-founder Joe disclosed the incident on X, assured customers that user funds remain safe, and said operations would resume after the investigation and wallet replenishment are completed.

The incident surfaced through suspicious transactions spanning several blockchains. Blockchain security firm Scam Sniffer initially reported about $4.2 million in abnormal outflows from Duelbits hot wallets on Ethereum, BNB Chain, and Tron to newly created addresses.

The firm assessed the activity as a suspected private-key compromise. Investigators later identified 8.1 BTC leaving the company’s Bitcoin hot wallet, increasing reported losses to approximately $7 million.

On Ethereum, the affected wallet transferred 836 ETH, roughly 593,000 USDT, 97,000 USDC, 31,500 DAI and 12.4 billion SHIB within minutes. Additional outflows included 209 BNB and 192,000 TRX. Most stolen assets were converted into Ether and consolidated into a single address holding around 2,234 ETH, valued at approximately $6 million when traced.

Although the transaction pattern indicates unauthorized control of wallet-signing capabilities, Duelbits has not released a technical root-cause analysis. The suspected private-key exposure therefore remains a security researchers’ assessment, not a confirmed conclusion.

If signing credentials were compromised, attackers could authorize valid-looking transfers without exploiting a smart contract, making immediate credential rotation and wallet isolation critical.

In updates, Joe said Duelbits had identified what happened and promised an official statement within 24 hours. He estimated that the website could return within 15 hours, while cautioning that engineers were rebuilding the platform’s deposit and withdrawal servers to ensure the infrastructure was secure. The company apologized for the disruption and said the work is intended to prevent a repeat incident.

Duelbits’ recovery plan includes completing the investigation, replenishing hot wallets, restoring services and launching Duelbits 2.0. Keeping the platform offline reduces exposure while engineers can rotate keys, review privileged access, reconcile balances and validate transaction systems.

However, the company has not yet explained the access vector, the wallet-custody architecture involved, or whether incident-response specialists and exchanges are assisting with asset recovery.

Customers should use only Duelbits’ official website and verified social accounts for updates. They should avoid unsolicited refund or recovery messages and never share seed phrases, passwords, or authentication codes, as criminals exploit high-profile cryptocurrency incidents by impersonating others and using phishing.

Duelbits maintains that customer balances are protected and says the platform will return stronger. Nevertheless, the incident remains active until its statement documents the confirmed root cause, affected systems, stolen assets, and safeguards.

Independent verification of resumed deposits and withdrawals will be essential for rebuilding trust after the $7 million Duelbits hack.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Duelbits Confirms $7 Million Hot-Wallet Hack, forcing Systems offline appeared first on Cyber Security News.