In Brief:
- Duelbits has paused operations after losing approximately $7 million from its hot wallets due to a compromise on September 24.
- The attack appears to stem from a private key issue, not a contract exploit, with stolen assets routed through various chains and consolidated into a single wallet.
- This is the second security breach for Duelbits in two years, highlighting ongoing issues in key management and the vulnerability of operational wallets.
Duelbits hit by hack, operations suspended
Duelbits has taken its platform offline following a security breach that resulted in the loss of around $7 million from its hot wallets. The attack, which occurred on September 24, has prompted the team to investigate the incident while they refill the drained wallets.
Initial reports suggest the breach is linked to a private key compromise rather than a smart contract vulnerability. Assets were siphoned from hot wallets across Ethereum, BNB Chain, Tron, Bitcoin, and Solana before being moved through a series of newly created addresses.
Details of the stolen assets
The majority of stolen funds were swapped into ether, with a consolidation address currently holding about 2,234.6 ETH, valued at approximately $5.96 million based on ether’s price at $2,666 on the day of the incident. This address remains static, showing no subsequent movement of the funds.
Onchain data from Etherscan indicates that three wallet addresses funneled assets into the consolidation address. An intermediary wallet ending in a1d7 sent the largest share, amounting to 1,601 ETH worth about $4.27 million. Another intermediary, ending in 8cD23, and a third address linked to the stolen bitcoin, contributed smaller amounts.
The hot wallet involved in the breach now holds less than $25.
Extent of the breach
In total, the attacker moved 836 ETH, around 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB. Additional outflows included 209 BNB, 192,000 TRX, and 8.1 BTC. The initial estimate for the breach was $4.2 million, but this figure increased to approximately $7 million once all chain losses were accounted for. Blockchain security firm Scam Sniffer first flagged the incident, drawing attention to the routing patterns familiar in such attacks.
Response from the platform
Duelbits co-founder Joe confirmed the breach and stated: “Confirming a ~$7M hack. Still investigating exactly what happened and how.” He emphasized that user funds remain secure, as the platform maintains a separation between hot and cold wallets. While hot wallets manage immediate deposits and withdrawals, the majority of user funds are stored offline.
The platform will remain offline until the investigation concludes and the hot wallets can be restored, at which point a relaunch will follow.
Previous breaches and ongoing concerns
This incident marks Duelbits’ second notable breach in two years, following an event in February 2024 that resulted in a loss of about $4.6 million. Together, the two breaches account for nearly $11.6 million. Repeated hot wallet compromises at the same operator raise questions about key management practices rather than signaling a specific exploit. Duelbits holds a license from the Curacao Gaming Authority.
Long-term implications of private key issues
Private key compromises have emerged as the leading cause of large crypto losses, outpacing smart contract bugs. While audited contracts are scrutinized, hot wallet keys can be phished or compromised through less secure infrastructure. For platforms that require constant deposits and withdrawals, a hot wallet’s balance can be exploited if an attacker obtains the key.
The consolidation address associated with the stolen funds remains motionless, providing investigators and exchanges ample time to monitor it.
Significance for crypto gaming
Although Duelbits operates as a gambling platform, the vulnerabilities it faces mirror those in onchain games. Many web3 titles employ hot wallets for in-game transactions, which can expose them to similar risks. For players, the key takeaway is that custodial risks persist whenever assets are held in a platform’s wallet. Transitioning valuable items and tokens to self-custodied wallets can mitigate this exposure entirely.