Major Security Breach at Duelbits: $7 Million Drained from Hot Wallets
The crypto community was alerted on September 25th following a report by CoinDesk detailing a significant security incident at the platform Duelbits. Approximately $7 million in assets were stolen from its hot wallets, with early indications pointing to a potential private key compromise. This marks another high-value attack targeting assets held by a centralized service.
The Attack Vector and Fund Movement
Blockchain security firm Scam Sniffer was among the first to identify suspicious activity. Monitoring data revealed that multiple Duelbits hot wallet addresses on Ethereum, BNB Chain, and Tron networks initiated large transfers to newly created addresses within a short timeframe.
- Ethereum Network: 836 ETH was transferred out, along with approximately 593,000 USDT, 97,000 USDC, and 31,500 DAI.
- Other Assets: The outflow also included 12.4 billion SHIB tokens. Separately, the platform's Bitcoin hot wallet lost 8.1 BTC.
On-chain analysis shows a coordinated effort by the attacker. Most of the stolen stablecoins and tokens were swiftly swapped for ETH and consolidated into a new address holding roughly 2,234 ETH (valued at around $6 million). As of this reporting, these funds have not been moved further.
Platform Response and Fallout
Following the incident, Duelbits co-founder Joe confirmed the loss via social media platform X. In a statement, he said, "We can confirm a security incident involving our hot wallets with a loss of approximately $7 million. Importantly, user funds are safe and unaffected."
To facilitate a thorough investigation and implement necessary fixes, Duelbits has suspended all platform services until the internal review is complete and the hot wallet reserves are replenished. This unplanned downtime has inconvenienced users and starkly highlights the persistent security challenges in crypto asset custody.
The community and several security firms are now tracking the movement of the stolen funds. This breach not only exposes potential vulnerabilities in private key management but also raises renewed questions about the operational safeguards for hot wallets at centralized exchanges.