Online casino **Duelbits** fully halted its service immediately after suffering the theft of cryptocurrencies worth approximately $7 million from hot wallets spanning four blockchains. The attacker later swapped most of the stolen assets for Ethereum (ETH) and moved them to a single wallet.
Key details
Duelbits acknowledged a hot wallet outflow of approximately $7 million, saying the site was temporarily suspended but that customer deposits are safe.
On-chain analytics firm Scam Sniffer is tracking suspicious transactions carried out on networks such as Ethereum, the BNB Chain, Tron, and Bitcoin (BTC), but the exact intrusion path has not yet been identified.
Most of the stolen assets were swapped into ETH and then concentrated into a single address holding about 2,234 ETH (worth approximately $6 million at the time).
Ethereum wallet hot wallet leaked
Scam Sniffer said it first detected abnormal withdrawals from Duelbits’ hot wallets on Ethereum, the BNB Chain, and Tron, and also confirmed that 8.1 BTC had drained from another wallet. After that, Duelbits co-founder **Joe** admitted to a hacking incident worth about $7 million and announced that it would keep the casino offline while the investigation is underway.
Jo said, “We confirmed that a hacking incident worth about $7 million occurred. We are investigating exactly what path and method were used.” He claimed the customers’ assets are safe. However, Duelbits did not provide any specific explanation about how the attacker managed to obtain access to the wallet, and through external coverage, the company’s claim of “no issues with customer assets” has not been independently verified on its own.
According to on-chain data, in the implicated Ethereum wallet, 836 ETH, about 593,000 Tether (USDT), 97,000 USD Coin (USDC), 31,500 Dai (DAI), and as many as 12.4 billion Shiba Inu (SHIB) were transmitted in a chain within just a few minutes. After that, a substantial portion of these assets was exchanged for ETH, and the analysis indicates that they were ultimately consolidated into a single address holding about 2,234 ETH (approximately $6 million at the time).
Related article: Bitget Confirms $351.6M Breach And Suspends All Withdrawals
Scam Sniffer analysis
Scam Sniffer weighs the likelihood of the wallet’s private key being leaked based on the speed and pattern of the capital outflow in this incident. This type of incident occurs not by exploiting vulnerabilities inherent to the blockchain itself, but by having the wallet owner’s keys stolen and thereby taking over full control of the wallet.
However, Duelbits has not yet officially acknowledged this hypothesis, and while the platform is working on hot wallet recharging and service restoration, it is focusing on identifying the exact intrusion route.
Meanwhile, the fact that the attacker converted stablecoins into ETH is seen as an element that could further reduce the likelihood of recovering the assets. Centralized issuers such as USDT and USDC can, under certain conditions, directly freeze assets, but because Ethereum has no issuer entity like that, intervention on the same level is essentially impossible. As of the time of analysis, no additional transfers were confirmed from the wallet address holding 2,234 ETH.
Meanwhile, Duelbits already experienced a hot wallet leak incident in February 2024 as well. According to security firm Halborn, at that time too, a security vulnerability was exploited and about $4.6 million reportedly left the company. As with this incident, it has again revealed the structural limitation that hot wallets kept continuously connected online for fast processing expose users to higher access risk than cold wallets.
Next article: Bitget Faces Suspected $177M Wallet Breach, On-Chain Data Shows
