Security

Duelbits Lost $7 Million. Check Your Own Wallets Against It

Duelbits went offline after a $7M hot-wallet hack. Run this checklist on every platform holding your crypto, including a mining pool.

One compromised key fanning out to Duelbits hot wallets on ETH, BNB, TRON and BTC, all draining into a single 2,234 ETH attacker address

Duelbits, one of the larger crypto casinos, took its own website offline on Thursday, September 24, 2026, after attackers drained roughly $7 million from its hot wallets on Ethereum, BNB Chain, Tron and Bitcoin, according to CoinDesk's report on the breach. The Duelbits hack is a useful checklist for anyone who keeps crypto on a platform, including miners who never think of their pool as one.

What Happened in the Duelbits Hack

Security firm Scam Sniffer flagged the outflows first. The Ethereum hot wallet alone sent 836 ETH plus stablecoins and SHIB to the attacker within minutes, and the Bitcoin hot wallet lost 8.1 BTC. The attacker swapped most of the haul into ether and parked it in one address holding about 2,234 ETH, worth roughly $6 million, which had not moved at the time of CoinDesk's report. A co-founder confirmed the breach on X, said user funds were safe, and promised the site would stay offline until the investigation ended and the team refilled the hot wallets.

Investigators suspect a private key compromise, not a smart contract bug or a phishing page that fooled a user. Somewhere, a key that controlled real funds ended up in the wrong hands, and everything that key controlled moved on command.

Duelbits has been here before. In February 2024, an attacker drained about $4.6 million from its wallets the same way. Whatever the company changed between then and now, it kept the basic setup: a company holding a pool of assets under keys it controls, on behalf of people who hold no key themselves.

That setup is not unique to gambling sites. Exchanges, custodial wallets and lending apps share it, and so does, in a related way, a mining pool that pays out from its own balance instead of paying a miner's coinbase directly. Run the checklist below against whatever holds your funds right now.

The Duelbits Hack Checklist

  • Can the platform move my funds without a signature only I control? If yes, as with Duelbits' hot wallets, a compromise anywhere inside that platform is a compromise of your balance too, even if nobody touched your device or password.
  • Does my balance exist as an entry in someone else's database, or as a payment that already landed in my own address? A database entry is a promise. A confirmed on-chain payment to an address only you hold the key to is settled.
  • If one backend or one key falls, does my share move with everyone else's? Duelbits users have now learned this twice. Bitget customers learned a version of it a few hours later the same day, when roughly $351.6 million left the exchange's hot and warm wallets after attackers spoofed its own authorization process rather than stealing a key.
  • For a mining reward: does the coinbase transaction pay a pool balance first, or my address directly? Most solo miners never check this one. On NexusPool, the coinbase pays the finder's own address in the same transaction that creates the block reward, and the pool takes 0%, so a backend compromise finds no pool-held balance to reach.
  • Can I check what the platform claims about my funds, or do I only have its word? Each hour, NexusPool publishes a signed receipt for the work it counted, a BIP340 signature against a key it publishes, and you can check it on the home page or in your own code. We call this the Glass Ledger: for each rig, the shares counted, the difficulty they were served at, and the window they landed in, signed and checkable.

Duelbits runs casino games and Bitget runs a full exchange, but the checklist ignores that difference. It asks one thing: when something inside the platform breaks, whose funds move? A gambling site, a spot exchange, a lending app and a mining pool that settles rewards into its own balance before paying miners all carry the same shape of risk under different branding. NexusPool's about page explains how a pool can avoid that shape, including the parts of the design that exist so nothing sits in a central balance waiting to be taken.

What to Do If the Duelbits Checklist Flags a Platform

If you answered yes to the first question and to the third for a platform you use today, that platform can lose your funds to one backend failure the way Duelbits and Bitget just did, whatever its security marketing says. The fix is unglamorous: keep only what you actively trade or play with on a platform like that, and move anything you would hate to lose into a wallet only you control.

If the fourth question applies to a mining setup you run, learn the difference before it matters. A pool that pays a balance first and settles with you later has one more place for something to go wrong than a pool whose coinbase transaction names your address from the start. That difference depends on how the payment is built, not on any company's promises holding up.

None of this makes solo mining risk-free, and nobody can independently audit NexusPool's software today, because it is not open source. Nothing here improves your odds of finding a block either. Those odds come from your hashrate divided by network difficulty, and they are identical at every pool, NexusPool included. How a payout is built changes only what happens to the reward after someone finds a block.

Trust nothing. Verify who can move your funds before a headline makes you ask.