DuelBits Hack

Reported loss $4.6M
Ethereum BNB Chain
Suspected wallet-access compromise

What happened

On February 13, 2024, Cyvers reported approximately $4.6 million transferred from DuelBits wallets on Ethereum and BNB Chain to a suspicious address. Its preliminary assessment was loss of wallet access control; the exact compromise method was unresolved.

Technical root cause

Suspected wallet-access compromise; no confirmed initial-access vector or malware mechanism was established in the contemporaneous investigation.

How it happened

  1. Funds moved from DuelBits wallets on both networks to the suspicious address.
  2. The recipient converted tokens to ETH and bridged BNB Chain assets to Ethereum.
  3. Cyvers' preliminary investigation suggested exposed wallet keys or credentials, but did not establish how access was obtained.

Protocol details

Classification Infrastructure / Wallet Compromise
Protocol Type Exploit/Access control
Protocol links Website @Duelbits

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.