Advertisement

Watch four AI agents manage money in public.

Subscription opening soon. Not financial advice.

Hack Database

Duelbits: Crypto Casino Loses $7M to Hackers, Its Second Raid in Three Years

Hackers emptied crypto casino Duelbits' hot wallets on five networks for about $7M, using the same wallet it set up after a $4.6M theft in 2024.

Duelbits: Crypto Casino Loses $7M to Hackers, Its Second Raid in Three YearsLogo: Duelbits (duelbits.com)
Duelbits, a crypto casino, says its customers' money was not touched.

Key numbers

  • $7M

    Stolen

  • $6.07M

    Traced on-chain

  • 1,370 ETH

    Into Tornado Cash

  • Unknown

    Attacker

At 08:58 UTC on 24 September 2026, 476,058 USDT left a wallet on the Tron network that belonged to Duelbits, an online casino and sports-betting site that takes its bets in cryptocurrency. USDT, issued by the company Tether, is a stablecoin: a digital dollar meant to be worth exactly one US dollar. One minute later, 552,762 more USDT left a Duelbits wallet on BNB Chain. Within four minutes the same wallet address, on Ethereum, had sent out a further 593,430 USDT, 96,805 USDC, 31,515 DAI, about 12.4 billion SHIB and 836 ETH. Nobody at Duelbits had asked for any of it.

By the afternoon Joe, a Duelbits co-founder who posts on X under that first name only, was "confirming a ~$7M hack" and saying the team was "still investigating exactly what happened and how." He added that user funds were safe. The site went dark for nearly three days.

It was the second time. In February 2024 the same casino lost about $4.6 million in what security firms also suspected was a stolen key, replaced the wallet that had been robbed, and published the new address. That replacement wallet is one of the wallets drained in September 2026.

Advertisement

Powered by Cyntri AI

The technology behind this newsroom. Built by Cyntri AI.

AI-assisted publishing, content pipelines and analytics. Crypto Media Zone is our working example.

Powered by Cyntri AI

Who Duelbits is

Duelbits was founded in 2020 and operates under a gaming licence from Curaçao, the Dutch Caribbean island that licenses a large share of the world's crypto casinos. It is not a small back-room operation. In the 2022/23 Premier League season it was Aston Villa's official European betting partner, with its name on the advertising boards at Villa Park. In 2023 it replaced the car seller Cazoo as title sponsor of three World Snooker Tour events, including the Tour Championship. It has also signed the footballer Luis Suarez as a brand ambassador, and in 2024 it won Best Crypto Operator at the EGR Operator Awards in London.

In an April 2026 blog post, Duelbits wrote under the heading "Track record" that it had operated since 2020 and that "no security breaches, hacks, or unauthorised fund access incidents have been reported in that time." The same page said player money sat in "offline, air-gapped wallets." Rekt News, the crypto incident site, pointed out on 6 October that the first claim contradicted Duelbits' own February 2024 statement admitting a "security breach" and an "unauthorized withdrawal."

How the money got out

A crypto business keeps its customers' money in two places. Most of it sits in cold storage, wallets kept offline, like cash in a bank vault. A smaller float sits in hot wallets connected to the internet, the equivalent of the cash drawer at the counter, so that winnings can be paid out in seconds. Any wallet, hot or cold, moves money only when a transfer is signed with its private key, a long secret number that works like the only signature a bank will ever accept. Whoever holds the key can move the money, and the blockchain does not ask who they are.

The pattern on 24 September looked like a stolen signature. Step one: a wallet on Tron was emptied. Step two: within a minute the BNB Chain wallet followed. Step three: the same address on Ethereum sent out its stablecoins and tokens, then its 836 ETH at 09:02 UTC. Step four: at 09:42 UTC, 8.1 bitcoin left a Duelbits bitcoin wallet in a single transaction that gathered 121 smaller deposits. A Duelbits wallet on Solana was also emptied of about 5,326 SOL, 397,880 USDC and 44,850 TRUMP, the Trump-branded meme coin. Everything went to fresh addresses the attacker controlled.

No code was broken to do this. There was no smart contract, the kind of program that moves money by itself, to trick. Scam Sniffer, a crypto security firm that was first to raise the alarm at 09:52 UTC, called it a "suspected private key compromise", and the security firm SlowMist lists the method as "Private Key Leakage." That is an assessment, not a finding. Duelbits has not said how the attacker got the ability to sign.

Joe hinted at something. Late on 24 September he said Duelbits had "identified what happened", promised an official statement within 24 hours, and said the team was rebuilding its deposit and withdrawal servers "to make sure everything is 100% secure." He also wrote that "a few people ruined it for everyone else", without saying who they were or what they did. As of 10 October 2026 the promised statement has not been published.

Counting the loss

Bar chart: loss estimates on 24 September rose from $4.2 million at 09:52 UTC to $7 million at 13:38; the later on-chain trace found $6.07 millionCMZ chart. Data: Rekt News, Unchained, CoinDesk
How the estimate grew on the day.

The estimates climbed all morning. Scam Sniffer first saw about $4.2 million on Ethereum, BNB Chain and Tron. PeckShield, another security firm, put it at about $4.3 million at 10:15 UTC. Specter, an independent on-chain investigator, reached about $4.9 million once the bitcoin was added. CertiK, the blockchain auditing firm, flagged about $6 million at 11:42 UTC. Duelbits' own figure, from Joe, is about $7 million.

Rekt News later traced every receiving address across all five networks, Ethereum, BNB Chain, Tron, Solana and Bitcoin, and valued what arrived at about $6.07 million. It noted that this does not reconcile with the $7 million Duelbits gave and that Duelbits has never published a chain-by-chain account. The $7 million is the victim's own number and the best available statement of what it lost. The $6.07 million is the part anyone can check.

Where the money went

The attacker turned almost everything into ether, the native coin of Ethereum, which is easier to move in bulk. PeckShield said the Ethereum and BNB Chain assets were swapped into about 1,588 ETH and 31,500 DAI. Seven transfers through deBridge, a service that moves coins between networks, carried a further 263 ETH from BNB Chain to Ethereum. On Tron the stolen USDT was swapped into about 1.4 million TRX. By the end of 24 September, CoinDesk counted about 2,234 ETH, worth roughly $6 million, in a single consolidation wallet.

It did not stay there. ChainBounty, a community investigation group, recorded 20 deposits totalling 1,370 ETH into Tornado Cash between 26 and 28 September. Tornado Cash is a mixer, a pool where many users' coins are blended so that what comes out cannot be matched to what went in. In stock-market terms it is a way of turning a traceable share certificate into untraceable cash. An independent trace published on GitHub counted about 1,012 ETH still sitting in the consolidation wallet on 3 October.

Nobody has been named. No security firm has attributed the theft to a known group, no law enforcement agency has announced an investigation, and no exchange has publicly announced a freeze of any of the funds.

The aftermath

Duelbits came back faster than most victims. On 25 September Joe published three wallets he said held about $8 million, in ether, Solana, BNB and stablecoins, to refill the hot wallets. At 05:04 UTC on 27 September the site reopened with deposits and withdrawals working. Duelbits said it had "taken the extra time to rebuild and test everything properly" and that around $8 million sat across hot and cold wallets, "ready to pay out." Players were told their deposit addresses had changed.

Publishing funding wallets is not the same as proving reserves. The addresses show what Duelbits said it put in, not what it owes its players, and no independent audit of player balances has been released. The company says no player lost a balance, so on its own account the $7 million came out of Duelbits' money rather than its players'.

The explanation promised for 25 September has not appeared. On 27 September Joe said he was still "working on an official explanation." Duelbits has not said how the attacker got control of the wallets, whether the 2024 and 2026 thefts are linked, what it changed after the first one, or whether any police force is involved. "Duelbits 2.0", an upgrade Joe had been promoting two days before the hack and listed as the last step of his recovery plan, was still described as coming soon when the site reopened. The April 2026 claim of a clean record since 2020 was the subject of open criticism by Rekt News on 6 October. About 1,370 ETH of the stolen money has gone through Tornado Cash and is effectively beyond tracing. No arrests have been made and nobody has been identified.

What this teaches

  • Replacing a robbed wallet is not the same as fixing whatever let the thief sign for it. Duelbits' 2024 replacement wallet was among those drained in 2026.
  • When the victim's figure ($7M) and the traceable figure ($6.07M) differ, both should be published, with a chain-by-chain account.
  • A marketing page that says there have been no breaches, written two years after an admitted breach, costs more trust than the breach did.
  • Reopening with a refilled cash drawer shows a company can pay out. It does not show what went wrong or that it cannot happen again.
  • A key that can empty five networks in under an hour is a single point of failure. Splitting signing power between several people or machines is the standard defence.
Advertisement

AI agents and automation

Could AI answer your customers from your own documents?

Assistants trained on your files, website and FAQs, with limits on what they can say. Fixed price before any work starts.

AI agents and automation