Duelbits confirms a significant cybersecurity incident that resulted in the theft of approximately $7 million from its hot wallets This article explores hot wallet breach. . The breach was reported by blockchain security firm Scam Sniffer, which noted suspicious withdrawals worth approximately $4.2 million from Duelbits-linked hot wallets on Ethereum, Binance Chain, and Tron.
The consolidation of a major cryptocurrency asset into an attacker's control can simplify their control over the funds, while also creating a visible on-chain trail for investigators, exchanges, and blockchain analytics firms. USER FUNDS ARE SECURE. HTTPS://T.CO/V4ZL4ST31I — Joe (@DuelbitsJoe) September 24, 2026 Despite the transaction activity indicating that attackers gained unauthorized access to the wallets' signing capabilities, Duelbits has not provided a formal technical root-cause analysis.
Duelbits’ recovery plan includes completing the incident investigation, replenishing hot-wallet liquidity, restoring services, and launching “Duelbits 2.0.” Keeping the platform offline provides engineers with time to rotate credentials, validate transaction systems, review access logs, and verify customer balances before reopening deposits and withdrawals. The company has not disclosed the initial access vector, the custody architecture used for the affected wallets, or whether incident-response firms, blockchain investigators, and exchanges are assisting with tracing and recovery efforts. Duelbits assures that user balances remain secure, but a detailed post-incident report and independent verification of restored transaction services will be crucial for rebuilding trust after the $7 million hot-wallet breach.











