Incident
Published 2026-09-24
Verified 2026-09-27

Duelbits (24 Sep): co-founder confirms ~US$7M hot-wallet drain; site offline pending rebuild

Crypto casino Duelbits co-founder Joe (@DuelbitsJoe) confirmed on X on 24 September 2026 a roughly US$7 million hot-wallet incident, stating the platform would stay offline until investigators finish root-cause work, re-top hot wallets, and bring services back (later update: site targeted ~15 hours; official statement promised within 24 hours; “user funds are safe”). On-chain researchers (Scam Sniffer) earlier flagged ~US$4.2M abnormal outflows from Duelbits hot wallets on Ethereum, BNB Chain and Tron to new addresses, later joined by ~8.1 BTC from a Bitcoin hot wallet — taking public loss estimates near US$7M. Ethereum-side sample flows cited in wire coverage include hundreds of ETH plus USDT/USDC/DAI/SHIB with consolidation toward a single address (~2,234 ETH at trace time). Suspected private-key / signing-path compromise is a researcher assessment; Duelbits has not published a technical root cause in the co-founder posts. Distinct from Bitget’s larger 24 Sep hot/warm wallet incident. Primary: co-founder X confirmation; wire: Cyber Security News 25 Sep.

Product
Duelbits cryptocurrency casino (hot wallets)
Versions
n/a (platform incident; root cause not yet in official post)
Exploited in Australia?
unknown
Patch to
Customers: use only verified Duelbits channels; treat phishing around the outage as likely; wait for the promised official statement before restoring large deposits. Operators: rotate hot-wallet keys / signing infra after any suspected key exposure; prefer cold/custody segregation.

Primary: Duelbits co-founder Joe — ~$7M hack confirmation (X, 24 Sep 2026) · Vendor: Duelbits co-founder follow-up — identified cause; statement pending (X, 24 Sep 2026) · Cyber Security News — Duelbits ~$7M hot-wallet (25 Sep 2026)

breaches cloud identity