TL;DR
On September 24, 2026, an attacker drained about $7 million from crypto casino Duelbits' hot wallets on Ethereum, BNB Chain, Tron and Bitcoin, and co-founder Joe confirmed "a ~$7M hack" on X while the site went offline. Scam Sniffer, which first flagged the outflows, assessed a suspected private key compromise. Duelbits has not published a root cause. On-chain, the Ethereum hot wallet was emptied in five transfers between 09:00:35 and 09:02:47 UTC, swapped into ETH, and consolidated into one address holding 2,234 ETH by 13:08 UTC, half an hour before the public confirmation. About 1,122 ETH of that pile traces directly to Duelbits' Ethereum hot wallet; the rest arrived through bridges or from addresses whose origin is not public. Since September 26 the attacker has pushed 1,370 ETH into Tornado Cash, and 973.5 ETH still sits at the consolidation address. It is the platform's second hot-wallet drain since February 2024, when it lost $4.6 million. The Ethereum hot wallet is a plain EOA, so on-chain nothing capped what its key could send, and whatever off-chain limits Duelbits ran did not stop five transfers in 132 seconds.
What Happened at Duelbits on September 24?
Duelbits lost roughly $7 million from the hot wallets that fund player withdrawals, and took the platform offline. CoinDesk's report credits blockchain security firm Scam Sniffer with first flagging the incident and lists the Ethereum hot wallet's outflow: 836 ETH, about 593,000 USDT, 97,000 USDC, 31,500 DAI and 12.4 billion SHIB, plus 8.1 BTC from the Bitcoin hot wallet. Most of it was swapped to ETH and pooled at one address holding about 2,234 ETH, roughly $6 million.
The first public number was smaller. PANews, relaying Scam Sniffer's monitoring, put it at about $4.2 million across Ethereum, BNB Chain and Tron: 836 ETH, 209 BNB, 192,000 TRX, 1.62 million USDT and 97,000 USDC, "suspected to be caused by a private key leak." Joe's post at 13:38 UTC raised it to about $7 million, promised to re-top the hot wallets and "launch Duelbits 2.0," and said user funds were safe.
Joe later said the team had identified what happened and that engineers were rebuilding the deposit and withdrawal servers, according to Cyber Security News, which also notes that Duelbits has not released a technical root-cause analysis. By September 27, ForkLog reported the relaunch, with Duelbits saying it held about $8 million across hot and cold wallets and that deposits and withdrawals were live. We have not found a formal incident report.
How Did a Single Key Empty the Ethereum Wallet in 132 Seconds?
A hot wallet is an online signing key that pays out without a human in the loop, so withdrawals clear in minutes. Duelbits' Ethereum hot wallet, the address that sent those exact amounts, is a plain externally owned account (EOA) with more than 170,000 transactions sent from it. An EOA has no contract logic, no pause, and no withdrawal limit. Whoever holds the key can sign anything. The receiving address needed no preparation either: it was never funded in advance, and its first transaction of its own came at 09:26, paid for with the stolen ETH.
At 08:40 UTC it sent a 16,603.94 USDT transfer, the kind of payout a casino wallet makes all day. Twenty minutes later it sent its holdings, token by token, to an address with no prior history:
- 09:00:35, 31,515 DAI
- 09:00:59, 12,397,915,453 SHIB
- 09:01:23, 96,804.68 USDC
- 09:02:11, 593,430.32 USDT
- 09:02:47, 836 ETH
Five transfers. 132 seconds. The order follows the gas: the four tokens first, native ETH last, because the ETH pays the gas for every token transfer and can only leave once they are gone.
How the attacker got the key is unconfirmed. Scam Sniffer's reading is a private key compromise, and the on-chain shape agrees: ordinary signed transfers from the wallet's own key, no contract call, no approval abuse. Joe's remark about rebuilding "our deposit and withdrawal" servers points, in our reading, at the machines that hold or reach the signing keys as the place the attacker got in. Treat that as an inference until Duelbits publishes. If the key-theft reading holds, the weakness class is CWE-522: Insufficiently Protected Credentials.
Compare Bitget's $387.5M loss the same day, where the keys stayed put and a spoofed backend fed the signer forged instructions.
The Attack, Step by Step
All times UTC. Ethereum steps are on-chain observed; the other chains are as reported.
| # | When | What happened | Evidence |
|---|---|---|---|
| 1 | Sep 24, 08:40 | Ethereum hot wallet makes a routine 16,603.94 USDT payout | On-chain |
| 2 | 09:00:35 to 09:02:47 | Five transfers move the wallet's DAI, SHIB, USDC, USDT and 836 ETH to a fresh address | On-chain |
| 3 | Same day, exact times not published | BNB Chain and Tron hot wallets drained (209 BNB, 192,000 TRX, stablecoins); 8.1 BTC leaves the Bitcoin hot wallet | Scam Sniffer via PANews, CoinDesk |
| 4 | 09:08 to 09:46 | 465 ETH arrives at the first address as cross-chain fills (deBridge, Relay) and direct transfers; its own tokens are swapped to ETH, USDC after 26 minutes, USDT after 33 | On-chain |
| 5 | 12:12:59 | 1,587.88 ETH forwarded to a second address, which swaps the DAI and adds it | On-chain |
| 6 | 12:37 to 13:08 | Three feeder addresses send 1 ETH test transfers, then 2,233.7 ETH, to the consolidation address | On-chain |
| 7 | 13:38 | Joe confirms "a ~$7M hack"; Duelbits stays offline | X post |
| 8 | Sep 25, 11:07 | A further 99.04 ETH reaches the consolidation address | On-chain |
| 9 | Sep 26 09:21 to Sep 28 08:39 | 1,370 ETH enters Tornado Cash in 20 deposits | On-chain |
| 10 | By Sep 27 | Duelbits relaunches with $8M across hot and cold wallets | ForkLog |
The laundering path branches and loops back on itself, which the table flattens:
How Much Was Taken, and Which Number Should You Trust?
Duelbits' own figure is $7 million. The part we can trace from a Duelbits wallet to the attacker is the Ethereum leg, about 1,122 ETH, or roughly $3 million at the price implied by CoinDesk's 2,234 ETH for $6 million.
The first estimate, about $4.2 million, counted Ethereum, BNB Chain and Tron before anyone looked at Bitcoin. FairGambling, citing PeckShield, says the attacker swapped that haul into 1,587.87 ETH, worth about $4.2 million. That number checks out against the attacker's first address, which forwarded exactly 1,587.88 ETH (10 ETH, then 1,577.88) at 12:12 UTC. The address's own history splits it into traced and inferred parts:
| Source of the ETH on the first address | ETH |
|---|---|
| 836 ETH taken directly from the Ethereum hot wallet | 836.0 |
| The hot wallet's USDC, SHIB and USDT, swapped through deBridge and Relay | 286.5 |
| Cross-chain fills from deBridge's DLN contract and Relay's router, 09:14 to 09:28 | 348.6 |
| Direct transfers from one unlabeled address, 09:08 to 09:20 | 116.8 |
| Forwarded at 12:12 UTC | 1,587.9 |
The 465 ETH in the last two rows reached the address between 09:08 and 09:28, nearly all of it before the address had swapped any token of its own, which is what bridged proceeds from other chains look like on arrival. We read it as the BNB Chain and Tron legs, but we have not traced those chains ourselves, so it counts as inferred.
Then the pile grew. Between 12:37 and 13:08 UTC, two more feeders added 632 ETH to the consolidation address, and another 99.04 ETH came the next day. Their origin is not public. The attacker pooled them with the traced funds, which suggests they belong to the same haul, possibly including the Bitcoin leg, but on-chain they do not connect back to a Duelbits wallet. The 2,234 ETH snapshot that CoinDesk priced at roughly $6 million includes them. Joe's ~$7 million is the only figure that claims to cover everything.
Sources disagree on the cross-chain USDT total: 1.62 million per Scam Sniffer via PANews, 1.146 million per PeckShield via FairGambling. The Ethereum slice is exact, 593,430.32 USDT and 96,804.68 USDC, read from the transfers themselves.
Where Did the Money Go?
Most of it sat still for two days, then went into Tornado Cash. The handling was methodical, and it shows in the transactions.
Every large move was preceded by a test. A feeder sent 1 ETH to the consolidation address, the consolidation address sent 0.1 ETH back, and only then did 476.53 ETH follow. The same 1-ETH probe preceded the 155 ETH feed, the 650 ETH hop on September 26, and the 650 and 601 ETH hops on September 28. A 1 ETH probe ahead of every large transfer is the habit of an operator who checks each destination before committing to it.
Then the ETH sat for two days. CoinDesk noted the 2,234 ETH had not moved as of publication, and it stayed that way until September 26, when 662 ETH (11, then 1, then 650) went to an intermediate hop, 110 ETH of it reached Tornado Cash through a separate address, and 552 ETH came back to the consolidation address. On September 28 the attacker moved 1,252 ETH to a second hop, which passed about 1,262 ETH (topped up from elsewhere) to an address that made 18 Tornado Cash deposits in 18 minutes, twelve of 100 ETH and six of 10 ETH, 1,260 ETH in all. Across both routes that is 1,370 ETH in 20 deposits, all in Tornado's fixed denominations, and 973.5 ETH remains at the consolidation address as of September 29.
The thief also became a target. Twelve seconds after the 601 ETH transfer on September 28, a dust transfer arrived from a lookalike address sharing the real hop's first and last characters, the address-poisoning setup that waits for someone to copy a destination from their history. Lookalikes of the consolidation address, two feeders and both hops followed, some sending fake tokens with homoglyph tickers. Others simply asked: an on-chain message reading "donate some eth pls" landed eleven minutes after the first test transfer into the consolidation address.
None of this points at an actor. Nobody has attributed the attack, and we do not.
Has Duelbits Been Hit Like This Before?
Yes. Halborn's review of February 2024 records DuelBits losing $4.6 million when an attacker drained tokens from the project's hot wallet, and FairGambling notes that attack hit wallets on Ethereum and BNB Chain. ForkLog ties the 2024 loss to the same suspected cause, a compromised private key. We have not found a published root cause for either incident. Two and a half years apart, the shape repeats: hot wallets on more than one chain, drained by whoever could sign for them.
The named precedent for casino hot wallets is Stake. The FBI attributed the theft of about $41 million from Stake.com on or about September 4, 2023 to the Lazarus Group, with stolen funds moved across Ethereum, BNB Smart Chain and Polygon. Crypto casinos make attractive targets for a structural reason: their business model requires large, always-online balances that pay out automatically to strangers.
If the relaunch rotated keys inside the same setup, the exposure is back where it was. The relaunch figure, $8 million across hot and cold wallets, is about what was lost. How that splits between hot and cold is the number that matters, and it has not been published.
Why Does One Hot Wallet Key Equal the Whole Float?
An EOA has no layer between the key and the chain that can refuse a transfer. A smart contract can enforce a daily limit, a timelock, or a pause. An EOA enforces only the signature. Hot-wallet security therefore has two halves: protecting the machine that holds the key, and capping what the key controls.
The industry's reflex after a hack is to ask who audited the code. Duelbits' loss involved no contract at all. An audit certifies the contracts you showed the auditor, on the day you showed them; it has nothing to say about a signing server, a float sized to a week of withdrawals, or a key that can send five assets to a stranger in 132 seconds.
Triple-A's $11.8M hot wallet compromise followed the same pattern, and the key-compromise runbook we wrote after Humanity Protocol covers the response side.
What Should Operators of Custodial Hot Wallets Do Now?
- Size the hot wallet to a few hours of withdrawals. Keep only what the next few hours of withdrawals need, and refill from cold storage on a schedule a human approves. Duelbits' Ethereum wallet held five assets worth millions while paying out five-figure withdrawals.
- Put a policy layer between the key and the chain. Use a smart-contract wallet or an MPC signing service that enforces per-transaction and per-hour outflow caps, so a stolen key can move only a capped amount.
- Separate keys per chain and per asset tier. One compromise should cost one wallet. Here four chains' hot wallets were hit the same day, and ETH that looks like the other chains' proceeds (direct transfers from 09:08, bridge fills from 09:14) was landing on the attacker's address within minutes of the Ethereum drain. That suggests the keys shared a place to be stolen from.
- Alert on the shape of a drain, and wire the alert to an action. Two different assets going to the same never-seen address is visible by the second transfer, 24 seconds in.
- Have issuer freeze requests ready before you need them. USDT and USDC can be frozen by Tether and Circle. Keep the contacts and the evidence template on hand. In this case the stablecoins were swapped away within 33 minutes.
- After a compromise, rebuild the architecture around the keys. Rotating keys on the same servers restores the pre-incident exposure. Publish what changed, so users can judge the fix.
Where Does Monitoring Fit in an Attack Like This?
The key signed ordinary transfers, and an EOA cannot be paused on-chain, so no alert stops the first one. What alerting changes is everything after it, and this drain left a readable trail. The first transfer sent 31,515 DAI to an address with no history, twenty minutes after a routine 16,603.94 USDT payout. Twenty-four seconds later the same new address took 12.4 billion SHIB, then the USDC, the USDT and the 836 ETH, all within 132 seconds. The stolen 96,804.68 USDC then sat on that address until a swap at 09:27:35, and the 593,430.32 USDT until the first Relay transfer at 09:35:47: 26 and 33 minutes on an address Tether and Circle could have frozen. Nothing was frozen, and the address holds no USDT or USDC today. Issuer freezes are not instant either, and after the Bitget theft the same day Circle and Tether froze about $318,000 on an exploiter address hours after the drain, so only a request filed in the first minutes races the swap. The public confirmation came 4 hours and 38 minutes after the first transfer. Tripwire is built to alert on this class of on-chain event: several assets leaving one wallet for the same never-seen address within minutes. The multi-asset rule fires on the second transfer, at 09:00:59, before the USDC, USDT and ETH had left the wallet. That is the earliest possible moment to file a freeze request, with both stablecoins still sitting where an issuer could reach them.
For the signing path itself, the servers that hold or reach hot-wallet keys are where a full security review should spend its time: how keys are stored, who can reach them, and what policy sits in front of them.
Frequently Asked Questions
How much did Duelbits lose in the September 2026 hack?
About $7 million, per co-founder Joe. Scam Sniffer's first estimate was $4.2 million across Ethereum, BNB Chain and Tron, and about 1,122 ETH traces directly from the Ethereum hot wallet to the attacker, with another 465 ETH arriving through bridge fills and an unlabeled address, likely from the other chains. The attacker's consolidation address held 2,234 ETH, roughly $6 million, by the end of September 24, including 632 ETH whose origin is not public.
Were Duelbits user funds affected?
No, according to Duelbits. Joe said user funds are safe, and the platform relaunched by September 27 saying it held $8 million across hot and cold wallets and that deposits and withdrawals were live. Duelbits has not published an incident report.
Was the Duelbits hack a private key compromise?
Not confirmed. Scam Sniffer assessed a suspected private key compromise, and the on-chain pattern of ordinary signed transfers fits it. Duelbits says it identified the cause but has not published it.
Where are the stolen Duelbits funds now?
Partly in Tornado Cash: 1,370 ETH in 20 deposits between September 26 and 28. Another 973.5 ETH remained at the consolidation address as of September 29.
Sources / References
- Crypto casino Duelbits goes offline after $7 million hot wallet hack, CoinDesk
- Joe (@DuelbitsJoe) on X: "Confirming a ~$7M hack", X
- Duelbits multi-chain hot wallet suspected of private key leak, ~$4.2 million in assets drained, PANews
- Duelbits Confirms $7 Million Hot-Wallet Hack, forcing Systems offline, Cyber Security News
- Crypto Casino Duelbits Resumes Operations After $7M Hack, ForkLog
- Duelbits Hacked Again: Co-Founder Confirms About $7 Million Loss, FairGambling
- Month in Review: Top DeFi Hacks of February 2024, Halborn
- FBI Identifies Lazarus Group Cyber Actors as Responsible for Theft of $41 Million from Stake.com, FBI
- Circle and Tether Step In to Freeze Hacker Wallet After Massive Bitget Crypto Heist, CoinDesk
- CWE-522: Insufficiently Protected Credentials, MITRE
- Etherscan: Duelbits Ethereum hot wallet 0x014435B1...CC9B
- Etherscan: 836 ETH from the hot wallet to the attacker's first address
- Etherscan: attacker's first address 0xA77e...ef76
- Etherscan: 593,430.32 USDT from the hot wallet
- Etherscan: 31,515 DAI, the first drain transfer
- Etherscan: routine 16,603.94 USDT payout at 08:40 UTC
- Etherscan: consolidation address 0x8db9...c306
- Etherscan: Tornado Cash depositor 0x5664...09Fc
- Etherscan: Tornado Cash depositor 0xAdb8...C578
- Etherscan: lookalike dust transfer 12 seconds after the 601 ETH hop
- Etherscan: "donate some eth pls" on-chain message



