In a recent cybersecurity breach, Duelbits, a well-known crypto casino, has reported a significant hack involving its hot wallets. The platform disclosed that approximately $7 million was drained, leading to its temporary shutdown. This measure aims to facilitate a comprehensive investigation into the source of the attack.
Investigation and Immediate Response
Joe, a co-founder of Duelbits, announced the breach on a social media platform, assuring users that their funds remain secure. He highlighted that the platform would resume once the investigation concluded and the wallets were replenished. Indicating proactive measures, Joe noted that the company is focused on understanding the breach’s specifics before restoring operations.
The cybersecurity incident came to light following the observation of suspicious transactions across multiple blockchains. Scam Sniffer, a blockchain security firm, initially detected unusual outflows totaling around $4.2 million from Duelbits’ hot wallets on Ethereum, BNB Chain, and Tron. These transactions suggested a potential compromise of private keys.
Details of the Breach
Further scrutiny revealed that the company’s Bitcoin hot wallet experienced an outflow of 8.1 BTC, raising the total losses to approximately $7 million. On Ethereum, the compromised wallet saw transfers of 836 ETH, around 593,000 USDT, 97,000 USDC, 31,500 DAI, and 12.4 billion SHIB in a short span. Additional assets, including 209 BNB and 192,000 TRX, were also moved. The stolen assets were largely converted to Ether, with the primary address holding about 2,234 ETH, valued at nearly $6 million at the time of tracking.
While these patterns indicate unauthorized access to wallet-signing capabilities, Duelbits has yet to provide a detailed technical analysis. The notion of private-key exposure remains speculative, based on security researchers’ assessments rather than confirmed findings.
Future Steps and Recovery
Joe informed users that the cause of the breach had been identified, with plans for an official statement within 24 hours. He estimated the platform could be operational again within 15 hours, as engineers work on rebuilding critical infrastructure to enhance security. This includes revamping deposit and withdrawal servers to prevent future incidents.
Duelbits’ recovery strategy involves completing the investigation, refilling hot wallets, and launching Duelbits 2.0. By keeping the platform offline, the company minimizes risk while undertaking key rotations and access reviews.
Despite the assurance of user fund safety, Duelbits has not clarified the breach’s access vector or if external specialists are aiding in asset recovery. Customers are advised to rely solely on official Duelbits channels for updates and to be wary of phishing attempts, which often follow such high-profile incidents.
The company remains confident in its ability to protect customer balances and plans to return with strengthened security measures. However, the incident is ongoing until a detailed report confirms the root cause and outlines the protective measures implemented.
