Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OnePlus OxygenOS Critical Flaws Let Zero-Permission Apps Gain Root Access
September 25, 2026
Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers
September 25, 2026
AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers
September 25, 2026
Home/CyberSecurity News/Duelbits Confirms $7 Million Hot Wallet Hack, Systems Offline
CyberSecurity News

Duelbits Confirms $7 Million Hot Wallet Hack, Systems Offline

Key Takeaways Crypto casino Duelbits suffered a security breach, resulting in approximately $7 million being stolen from its hot wallets. The platform has been taken offline as investigations into...

Emy Elsamnoudy
Emy Elsamnoudy
September 25, 2026 4 Min Read
7 0

Key Takeaways

  • Crypto casino Duelbits suffered a security breach, resulting in approximately $7 million being stolen from its hot wallets.
  • The platform has been taken offline as investigations into the root cause are underway.
  • User funds held in cold storage are reportedly safe, according to Duelbits co-founder Joe.
  • The incident is suspected to involve a private-key compromise, though an official technical analysis is pending.
  • Duelbits is rebuilding its deposit and withdrawal infrastructure and plans to relaunch with “Duelbits 2.0.”

The cryptocurrency gambling platform Duelbits has confirmed a significant security incident, announcing that approximately $7 million was illicitly siphoned from its hot wallets. This breach has prompted the company to take its entire system offline while a thorough investigation is conducted to pinpoint the precise nature of the attack.

Table Of Content

  • Key Takeaways
  • Initial Disclosure and User Assurance
  • Tracing the Illicit Transactions
  • Breakdown of Stolen Assets and Consolidation
  • Suspected Root Cause: Private Key Compromise
  • Update on Recovery and Future Plans
  • What You Should Do

Initial Disclosure and User Assurance

Joe, a co-founder of Duelbits, utilized the social media platform X to inform the public about the breach. He emphasized that all customer funds stored in cold wallets remain secure. Joe also stated that operations would resume once the investigation concludes and the affected hot wallets are fully replenished. His statement on September 24, 2026, confirmed the ~$7M hack and outlined next steps, including the launch of Duelbits 2.0. The initial message can be viewed at https://t.co/V4Zl4St31I.

Tracing the Illicit Transactions

The incident first came to light through a series of unusual transactions observed across multiple blockchain networks. Blockchain security firm Scam Sniffer was among the first to report suspicious outflows, initially identifying about $4.2 million in unauthorized transfers from Duelbits’ hot wallets on the Ethereum, BNB Chain, and Tron networks. These funds were directed to newly established addresses.

Scam Sniffer’s preliminary assessment pointed to a potential compromise of private keys. Further investigation subsequently revealed an additional 8.1 BTC had been withdrawn from the company’s Bitcoin hot wallet, elevating the total estimated loss to approximately $7 million.

Breakdown of Stolen Assets and Consolidation

On the Ethereum blockchain, the compromised wallet rapidly transferred a substantial amount of various cryptocurrencies. This included 836 ETH, approximately 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB within a short timeframe. Additional assets stolen included 209 BNB and 192,000 TRX. The majority of these pilfered assets were then converted into Ether and consolidated into a single address, which, at the time of tracing, held roughly 2,234 ETH, valued at approximately $6 million.

Suspected Root Cause: Private Key Compromise

While Duelbits has yet to release a detailed technical root-cause analysis, the pattern of transactions strongly suggests unauthorized control over the wallet’s signing capabilities. This leads security researchers to suspect a private-key compromise. If confirmed, this type of breach allows attackers to authorize legitimate-looking transfers without exploiting smart contract vulnerabilities. Consequently, immediate rotation of credentials and isolation of affected wallets become paramount.

Update on Recovery and Future Plans

In subsequent updates, co-founder Joe indicated that Duelbits had successfully identified the nature of the attack and promised a comprehensive official statement within 24 hours. He provided an optimistic estimate for the website’s return, suggesting it could be back online within approximately 15 hours. However, he also clarified that engineers were actively rebuilding the platform’s deposit and withdrawal servers to ensure the integrity and security of the underlying infrastructure. The company issued an apology for the service disruption, emphasizing that these efforts are aimed at preventing any future recurrences. This update was also shared on September 24, 2026, and can be found at https://t.co/Whd44cJSPV.

Duelbits’ recovery strategy encompasses a multi-stage process: finalizing the investigation, replenishing the hot wallets, restoring full services, and launching “Duelbits 2.0.” Keeping the platform offline during this period is a critical measure to limit further exposure, allowing engineers to rotate cryptographic keys, review privileged access, reconcile account balances, and rigorously validate all transaction systems.

As of now, Duelbits has not publicly detailed the specific access vector used by the attackers, the architecture of its wallet custody solutions, or whether external incident-response specialists and cryptocurrency exchanges are collaborating in the asset recovery efforts.

What You Should Do

  • Rely on Official Channels: Only seek updates from Duelbits’ official website and verified social media accounts.
  • Beware of Scams: Be highly suspicious of any unsolicited messages offering refunds or recovery services.
  • Protect Credentials: Never share your seed phrases, passwords, or authentication codes with anyone, as scammers often exploit high-profile incidents through phishing.
  • Monitor for Official Statement: Await Duelbits’ official statement detailing the confirmed root cause, affected systems, and new security measures.
  • Verify Resumed Services: Exercise caution and independently verify the functionality and security of deposit and withdrawal systems once the platform is back online.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCybersecurityExploitphishingSecurity

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

MacSync Malware Transforms macOS Apps for Crypto and Password Theft

Next Post

Critical Salesforce Bug Lets Attackers Steal Data via Prompt Injection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Sauron Loader Malware Evades Detection with DLL Side-Loading
September 25, 2026
Critical WordPress Comment2Shell RCE Vulnerability CVE-2022-0215 Patched
September 25, 2026
Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization
September 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us