Crypto casino Duelbits suspended operations on September 24, 2026, after a suspected private key compromise drained approximately $7 million from its hot wallets across multiple blockchains. Co-founder Joe confirmed the hack, stating that user funds remain safe in cold storage and that the platform will remain offline while rebuilding its servers. This marks the second major breach for Duelbits, which previously lost $4.6 million in February 2024.
Suspension of operations and recovery
- ▪Duelbits co-founder Joe stated on September 25, 2026, that the platform required additional downtime to secure the site, rebuild deposit and withdrawal servers, and refill its wallets.
- ▪Duelbits posted on September 25, 2026, that it was conducting final security checks and investigating the September 24, 2026 security incident affecting the site
- ▪Crypto casino and sports betting platform Duelbits suspended operations and went offline after hackers drained approximately $7 million from its hot wallets on September 24, 2026.
Details of the stolen assets
- ▪An attacker drained 836 ETH, approximately 593,000 USDT, 97,000 USDC, 31,500 DAI, 12.4 billion SHIB, 209 BNB, and 8.1 BTC from Duelbits wallets
- ▪Most of the stolen assets from the September 24, 2026 Duelbits hack were swapped for ether and consolidated into a single address holding about 2,234 ETH, worth roughly $6 million
- ▪The September 24, 2026 Duelbits hack targeted Duelbits hot wallets across multiple blockchain networks, including Ethereum, BNB Chain, Tron, Bitcoin, and Solana
Suspected private key compromise
- ▪The private key compromise suspected in the Duelbits hack was also the method used to target Stake, the largest crypto casino by volume, in a 2023 exploit that drained $40 million
- ▪Blockchain security firm Scam Sniffer flagged the Duelbits outflows from September 24, 2026, as a suspected private key compromise, which allows attackers to control wallets without exploiting smart contracts
Safety of user funds
- ▪Duelbits co-founder Joe assured users on X that user funds are safe and that customers will be able to withdraw immediately once operations resume after the September 24, 2026 hack
- ▪Duelbits maintains a separation between its operational hot wallets and user reserves, which are held in offline cold storage.
Past security incidents
- ▪The September 24, 2026 breach marks the second major security incident for Duelbits, which previously lost approximately $4.6 million in February 2024.
- ▪Security firm Halborn reported that an attacker in the February 2024 Duelbits hack exploited a security vulnerability to drain tokens from the platform's hot wallet
Other cryptocurrency hacks
- ▪Bitget CEO Gracy Chen stated that approximately $351.6 million was taken from the cryptocurrency exchange's hot and warm wallets during a September 24, 2026 hack.
- ▪TRM Labs reported 207 individual crypto hacks in the first half of 2026, totaling about $972 million in swiped funds, with the majority due to smart contract exploits.
Debatable claims
- ▪Duelbits has failed to maintain the security standards necessary to protect its users
- ▪Private key compromises are primarily the result of internal platform negligence
- ▪The convenience of instant withdrawals justifies the security risks of crypto hot wallets
Story comments
Loading comments…