Duelbits Reports $7M Hack and Takes Site Offline
Duelbits co-founder Joe estimates a $7 million hack. Verified transfers trace to its 2024 replacement wallet; cause remains unknown.
The September 2026 Duelbits hack has a link to an earlier incident: an Ethereum address the casino named as its replacement hot wallet in 2024 sent assets to a suspected recipient on September 24. Co-founder Joe put the preliminary loss at about $7 million and said Duelbits would remain offline while it investigates.

KEY FACTS AT A GLANCE
- Incident: Duelbits reported a security investigation and took its site offline on September 24, 2026.
- Loss estimate: Co-founder Joe described a roughly $7 million hack; the company has not published an asset-by-asset accounting.
- Wallet link: The Ethereum address Duelbits publicly announced as a replacement hot wallet in February 2024 appears as the source of September 2026 transfers on Ethereum and BNB Smart Chain.
- Cause and customer exposure: Neither a root cause nor independent proof of the status of player balances had been published by 15:21 UTC on September 24.
The 2024 replacement wallet appears in the new transfer trail
In February 2024, Duelbits said about 1,700 ETH had been withdrawn from an Ethereum reserve hot wallet. Its follow-up named 0x014435B1E39945CF4f5F0c3cbb5833195A95CC9B as the new Ethereum hot wallet. On September 24, 2026, that exact address was the sender of 836 ETH, 593,430.319280 USDT, 96,804.68323 USDC, 31,515 DAI and 12.398 billion SHIB to 0xa77e24fe29d16e051e487ef4ea7b056cb05aef76, an address flagged by blockchain investigators.
The same hexadecimal sender address also transferred 552,761.728670 USDT and 209 BNB on BNB Smart Chain. The address match ties Duelbits’ own 2024 wallet announcement to part of the 2026 transaction trail. It does not establish that the same person carried out both incidents or that the security failure was the same. The operator has not explained how the 2026 transfers were authorized.
The older incident matters because the wallet was presented as the replacement after a previous loss, not because it proves a repeated attack method. For wider context on how gambling operators have handled security incidents, see Dyutam’s casino cybersecurity timeline; the cases there involve different kinds of exposure.
How the September 24 Duelbits incident unfolded
The first identified transfer in this trail was 476,058.087528 USDT from a Tron address flagged as a Duelbits wallet at 08:58:36 UTC. A 552,761.728670 USDT transfer followed on BNB Smart Chain at 08:59:55. The Ethereum wallet sent several assets between 09:00 and 09:03, ending with 836 ETH at 09:02:47. These are blockchain confirmation times, not times when the operator or researchers first disclosed the incident.
A Bitcoin address identified by security researchers received 8.09987887 BTC in a transaction confirmed at 09:42:45 UTC. That transaction drew from multiple input addresses, so the public record alone does not prove that every input came from Duelbits. Researchers also flagged a Solana recipient associated by Solscan with a Duelbits hot wallet, but the accessible transaction sample does not support a reliable Solana loss total. Neither figure should be added mechanically to an operator loss estimate.
Scam Sniffer posted its first warning at 09:52 UTC. PeckShield followed at 10:15, and CertiK published its estimate at 11:42. Duelbits posted at nearly the same time that it was investigating a security incident and had taken the site offline. Joe’s later update described a roughly $7 million hack and said the company would investigate, replenish its hot wallets and then bring the site back online. CEO Jasper also said customer funds were safe. Those are operator statements, not an independent accounting of player liabilities or available reserves.
Why the reported loss ranges from $4.2 million to $7 million
The numbers were published at different times and covered different sets of chains. Scam Sniffer initially estimated about $4.2 million across Ethereum, BNB Smart Chain and Tron. PeckShield counted about $4.3 million on Ethereum and BNB Smart Chain. After identifying the Bitcoin receipt, Scam Sniffer raised its estimate to about $4.9 million. CertiK later reported about $6 million in suspicious outflows across several networks. Joe’s roughly $7 million figure came from the operator. No public, itemized reconciliation links those snapshots to the company’s estimate.
The USDT line shows one concrete reason two reports can differ. Ethereum and BNB Smart Chain transfers add to 1,146,192.047950 USDT, matching PeckShield’s rounded 1.146 million USDT figure. Add the separate 476,058.087528 USDT Tron transfer and the identified three-chain sum becomes 1,622,250.135478 USDT. These figures describe identified USDT movements, not the incident’s total dollar loss.
Further movements complicate any attempt to total the loss from a current destination-wallet balance. One Ethereum consolidation address held about 2,234 ETH at approximately 14:52 UTC on September 24, but it received mixed inputs. Treating that entire balance as Duelbits’ loss would overstate what the traced transfers prove.
What is known about player balances and withdrawals
Joe and Jasper both said user funds were safe. Duelbits has not published a balance-sheet snapshot, proof of reserves or a customer-by-customer withdrawal plan to substantiate that claim. Its own wallet guide describes balances held on the platform as custodial, and its fee guide says deposits are converted to in-platform “Bits” before being converted back to crypto for withdrawal. A customer’s displayed balance therefore cannot by itself show which assets remain available in the hot wallets used to process withdrawals.
At a 15:21 UTC check on September 24, duelbits.com redirected to a maintenance page. Dyutam could not establish a working withdrawal route or a reopening time. Duelbits’ ordinary withdrawal-help page describes manual review and support contact, but it was not written as an incident-specific guarantee. Players can retain transaction IDs and account records and use the operator’s published support channels for account-specific questions. Duelbits’ phishing guidance warns against unsolicited social messages and requests for wallet recovery phrases.
A license check can establish which company holds a gambling authorization; it does not audit the assets backing each customer balance. Dyutam’s casino licensing guide explains the checks a player can make. A separate gambling security case illustrates why incident claims and supporting records need to be kept distinct.
The unanswered questions
The company has not disclosed the intrusion route, whether a private key was compromised, the full chain-by-chain loss, or when normal operations will resume. Scam Sniffer raised a possible private-key compromise in its initial alert; it remains a hypothesis. The confirmed address reuse is a reason to ask how the replacement wallet was protected after 2024, but the public record does not answer that question.
FAQs
What happened in the Duelbits hack in 2026?
Duelbits said it was investigating a security incident and took its site offline on September 24, 2026. On-chain records show transfers from wallets identified with the operator, while co-founder Joe described the event as a roughly $7 million hack. The company has not published a root-cause report.
How much did Duelbits lose?
Co-founder Joe gave a preliminary estimate of roughly $7 million. Security researchers reported earlier snapshots from about $4.2 million to $6 million, depending on timing and network coverage. Duelbits has not released an itemized reconciliation.
Which blockchains and assets appear in the transfer trail?
Identified transfers include ETH, USDT, USDC, DAI and SHIB on Ethereum; USDT and BNB on BNB Smart Chain; and USDT and TRX on Tron. Researchers also flagged Bitcoin and Solana addresses, but public records do not support attributing every Bitcoin input or a complete Solana loss to Duelbits.
Was a wallet from the 2024 Duelbits incident involved again?
Yes. An Ethereum address Duelbits publicly announced in February 2024 as its replacement hot wallet sent assets to a flagged recipient in September 2026. The address match does not prove that the attacker or method was the same in both incidents.
Was a private key compromised?
That has not been established. Scam Sniffer suggested a possible private-key compromise in its initial alert, but Duelbits has not identified the intrusion route or published a forensic finding.
Are Duelbits customer funds safe?
Co-founder Joe and CEO Jasper said user funds were safe. That assurance had not been accompanied by a public balance-sheet snapshot, proof of reserves or account-level withdrawal evidence at the latest verified update, so the status of individual balances cannot be independently confirmed from their statements alone.
Can players withdraw, and where should they seek updates?
Duelbits said its site would stay offline during the investigation and gave no reopening time. Players should use the company’s verified site and support channels for account-specific updates, keep transaction IDs and account records, and avoid unsolicited messages asking for wallet recovery phrases.
KEY TAKEAWAYS
- About $7 million is an operator estimate: Duelbits co-founder Joe gave that preliminary figure; independent researchers published narrower snapshots without a public reconciliation.
- The 2024 address link is documented: Duelbits’ announced replacement Ethereum hot wallet sent assets to a flagged recipient in 2026. It does not establish a shared attacker or cause.
- Player-funds assurances remain unverified: Duelbits says customer funds are safe. At the 15:21 UTC September 24 check, its site still showed a maintenance page, and no independent accounting had been published.
Sources
- September 24 security incident notice — Duelbits
- Maintenance page displayed at 15:21 UTC on September 24 — Duelbits
- September 24 loss and operating update — Duelbits co-founder Joe
- September 24 customer-funds statement — Duelbits CEO Jasper
- February 2024 wallet incident statement and replacement hot-wallet announcement — Duelbits
- 836 ETH transaction, Ethereum USDT transaction, USDC transaction, DAI transaction and SHIB transaction — Blockscout
- BNB Smart Chain USDT transaction and BNB transaction — BscScan
- Tron USDT transaction and TRX transaction — Tronscan
- Bitcoin receipt transaction — mempool.space
- Ethereum consolidation address, observed at approximately 14:52 UTC on September 24 — Blockscout
- Flagged Solana recipient account and labeled funding wallet — Solscan
- Initial alert and Bitcoin update — Scam Sniffer
- Ethereum and BNB Smart Chain estimate — PeckShieldAlert
- Cross-chain estimate and listed addresses — CertiKAlert
- Crypto wallet custody guide, fees and processing guide, withdrawal help and phishing guidance — Duelbits



