en

Duelbits crypto hack drains $7M as casino goes offline

image
rubric logo Security

Crypto casino Duelbits has taken its site offline after attackers have siphoned approximately $7 million from its various wallets.

The company said that it is investigating the matter and assuring people that funds within accounts are unaffected. However, they are not commenting on how the attackers gained access to the systems or when the casino will be reopening.

Attackers drain wallets across four networks

Scam Sniffer [a company that specializes in blockchain security research] first detected a string of unusual transfers from Duelbits wallets on BNB Chain, Ethereum, and Tron. A loss of 8.1 $BTC from the $BTC wallet of Duelbits was later detected.

Affected wallets were “hot wallets”: online accounts where a platform would hold enough crypto to process clients’ deposits or withdrawals. This, while convenient for speedy transactions, puts them more at risk if somebody manages to gain access to credentials.

Duelbits co-founder Joe confirmed the incident, writing:

Confirming a ~$7M hack. Still investigating exactly what happened and how.

He said Duelbits would remain offline until the investigation was complete and when the company had replenished its hot wallets. But there’s yet to be an independent verification of the funds to know if they are safe as claimed.

The attacker received 836 $ETH, approx. 593,000 $USDT, 97,000 $USDC, 31,500 DAI, and 12.4 billion SHIB.

Because of the speed and scale of these withdrawals, Scam Sniffer suspects that a private key has been compromised.

The private key refers to master credentials to control a crypto wallet. If one obtains this, one potentially does not need to exploit any blockchain to effect transfers from the associated wallet.

Duelbits has not confirmed that explanation.

Stolen funds converted into Ether

Most of the stolen tokens were exchanged for Ether and brought together in a single address.

The address held about 2,234 $ETH, valued at roughly $6 million, following the transfers. The funds had not moved onwards at the time they were traced.

If the stolen assets are transferred across to Ether, this may make the recovery of such assets much harder.

The companies backing $USDT & $USDC are able to freeze these assets, whereas this is not possible when it comes to ether. There is no issuer for ether, like there is for assets such as $USDT & $USDC, that would be able to freeze it if taken as part of a cyber hack.

A handful of questions still remain unanswered. It is still a question how Duelbits wallet credentials may have been breached, and if customer deposits were placed in the affected wallets, and finally, when withdrawals will resume.

Duelbits has remained silent so far.

The customer should further be advised not to use refund or recovery links available during the time of the outage. Many links shared at such times lead to gaining wallet details and recovery phrases.


Final Summary

  • Duelbits recently announced that they got hacked for around $7 million across four different network wallets:
  • Most of the hijacked assets were swapped to Ether and are visible at one address.