Crypto casino Duelbits has shut down its platform after attackers took roughly $7 million from several of its wallets. In the Duelbits crypto hack, the stolen assets were moved across four blockchains, and most of them were then converted into Ether.
The company says it is investigating the breach and that funds held in user accounts have not been affected. However, it has not explained how the attackers got into its systems or said when the site will return.
Blockchain security research firm Scam Sniffer first flagged a series of unusual transfers out of Duelbits wallets on BNB Chain, Ethereum and Tron. Later, it spotted a further loss of 8.1 BTC from the casino’s Bitcoin wallet.
All the affected wallets were hot wallets. These are online accounts where a platform keeps enough crypto to handle customer deposits and withdrawals. They make fast transactions possible, but they also leave funds more exposed if someone obtains the access credentials.
The attacker ended up with 836 ETH, about 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB.
Duelbits co-founder Joe acknowledged the incident in a public post:
Confirming a ~$7M hack. Still investigating exactly what happened and how.
Until we have clarity, Duelbits stays offline. User funds are safe.
Next steps: finish the investigation, re-top hot wallets, and bring Duelbits back online, launch Duelbits 2.0.
I’ll keep posting updates as I have them.
Duelbits will be back up asap.
Updates to follow”
Joe said the platform would stay offline until the investigation is finished and the hot wallets have been refilled. No one has independently verified his claim that user funds are safe.
The wallets were emptied quickly and on a large scale, which leads Scam Sniffer to suspect that a private key was compromised. A private key is the master credential for a crypto wallet. Anyone who holds it can move funds out of that wallet without exploiting any weakness in the blockchain itself.
Duelbits has not confirmed this explanation.
Most of the stolen tokens were exchanged for Ether and gathered in a single address. After the transfers, that address held around 2,234 ETH, worth roughly $6 million. When the funds were traced, they had not moved any further.
Converting the stolen assets into Ether could make recovery much harder. The companies behind USDT and USDC can freeze those tokens. Ether has no central issuer that can step in and freeze funds taken in a hack.
Several important questions remain open. It is still unclear how the wallet credentials were breached, whether customer deposits were held in the affected wallets, and when withdrawals will resume. Duelbits has not addressed these points so far.
Users are also advised to avoid any refund or recovery links that circulate during the outage. Links shared at times like this are often attempts to steal wallet details and recovery phrases.
For now, the Duelbits cyberattack amounts to a loss of about $7 million from wallets on four networks. Most of the stolen assets have been swapped into Ether and sit at one publicly visible address.