In Brief:
- After a compromise on September 24 cost it about $7 million from its hot wallets, Duelbits has halted operations.
- The incident looks like a private key problem rather than a contract exploit. The stolen assets were routed across multiple chains and then gathered into one wallet.
- It is the second security breach at Duelbits in two years, which points to ongoing weaknesses in key management and in how exposed operational wallets are.
Duelbits suspends operations after hack
Duelbits has taken its platform offline after a security breach drained around $7 million from its hot wallets. The team is investigating the September 24 attack and refilling the emptied wallets.
Early reports link the breach to a compromised private key, not a flaw in a smart contract. Funds were pulled from hot wallets on Ethereum, BNB Chain, Tron, Bitcoin and Solana, then passed through a chain of newly created addresses.
Details of the stolen assets
Most of the stolen funds were converted into ether. A consolidation address now holds about 2,234.6 ETH, worth roughly $5.96 million at ether’s price of $2,666 on the day of the attack. That address has stayed dormant, and none of the funds have moved since.
According to onchain data from Etherscan, three wallet addresses fed assets into the consolidation address. The largest share came from an intermediary wallet ending in a1d7, which sent 1,601 ETH worth about $4.27 million. A second intermediary ending in 8cD23 and a third address tied to the stolen bitcoin sent smaller amounts.
Less than $25 now remains in the compromised hot wallet.
Extent of the breach
Altogether, the attacker took 836 ETH, around 593,000 USDT, 97,000 USDC, 31,500 DAI and 12.4 billion SHIB. Further outflows included 209 BNB, 192,000 TRX and 8.1 BTC. The first estimate put the damage at $4.2 million, but that rose to roughly $7 million once losses on every chain were counted. Blockchain security firm Scam Sniffer was the first to flag the incident, noting routing patterns that are common in attacks like this.
Response from the platform
Duelbits co-founder Joe confirmed the breach and said: “Confirming a ~$7M hack. Still investigating exactly what happened and how.” He stressed that user funds are safe because the platform keeps its hot and cold wallets separate. Hot wallets handle day-to-day deposits and withdrawals, while most user funds are kept offline.
Duelbits will stay offline until the investigation is finished and the hot wallets have been restored. The platform will relaunch after that.
Previous breaches and ongoing concerns
This is Duelbits’ second notable breach in two years. In February 2024, an earlier incident cost the platform about $4.6 million, bringing the combined losses from the two breaches to nearly $11.6 million. When the same operator’s hot wallets are compromised more than once, it raises questions about its key management practices rather than pointing to one specific exploit. Duelbits is licensed by the Curacao Gaming Authority.
Long-term implications of private key issues
Compromised private keys have overtaken smart contract bugs as the main cause of large crypto losses. Audited contracts get close scrutiny, but hot wallet keys can be phished or stolen through weaker infrastructure. Platforms that process deposits and withdrawals all the time need a funded hot wallet, and an attacker who gets the key can drain that balance.
The consolidation address holding the stolen funds has not moved, which gives investigators and exchanges plenty of time to watch it.
Significance for crypto gaming
Duelbits is a gambling platform, but its weak points are the same ones onchain games face. Many web3 titles use hot wallets for in-game transactions, which can leave them open to similar attacks. The lesson for players is that custodial risk exists whenever assets sit in a platform’s wallet. Moving valuable items and tokens into self-custodied wallets removes that exposure entirely.











STAY ALWAYS UP TO DATE