📈 Get daily crypto insights that make you smarter about your money

Inside the MetaWin Breach: How 115 Wallet Addresses Traced a 4 Million Dollar Crypto Casino Heist

The online cryptocurrency casino MetaWin fell victim to a devastating security breach on November 3, 2024, with attackers siphoning approximately $4 million from the platform’s hot wallets. The incident, which blockchain investigator ZachXBT publicly disclosed, exposed critical weaknesses in MetaWin’s so-called frictionless withdrawal mechanism — a feature designed for speed that ultimately became the attackers’ primary entry point.

The Exploit Mechanics

The attacker exploited MetaWin’s streamlined withdrawal infrastructure, which had been optimized for near-instantaneous transactions across both Ethereum (ETH) and Solana (SOL) networks. By targeting the platform’s hot wallets — digital wallets connected to the internet for real-time transaction processing — the malicious actor drained funds before the security team could detect the anomaly. ZachXBT identified 115 distinct wallet addresses connected to the attack, tracing the movement of stolen assets through KuCoin exchange and a nested service operating on HitBTC. These funneling techniques represent classic laundering patterns that complicate fund recovery efforts.

With Bitcoin trading at approximately $67,800 and Ethereum hovering around $2,397 at the time of the attack, the $4 million loss represented a significant blow to the relatively small platform. The attacker’s ability to access both ETH and SOL wallets simultaneously suggests a systemic vulnerability rather than an isolated point of failure.

Affected Systems

The breach impacted MetaWin’s core hot wallet infrastructure across two major blockchain networks. The platform’s Ethereum hot wallet and Solana hot wallet were both compromised, indicating that the vulnerability likely existed in the shared withdrawal processing layer rather than in network-specific implementations. MetaWin CEO Richard “Skel” Skelhorn confirmed the breach and immediately suspended all withdrawal operations to prevent further losses.

Approximately 95% of MetaWin’s user base eventually regained access to their funds following the incident. Skelhorn publicly stated that he used personal funds to partially cover the losses, telling the community, “I just emptied my piggy bank — we keep building.” The platform contacted federal law enforcement, and the investigation was handed over to authorities.

The Mitigation Strategy

In the wake of the attack, MetaWin implemented several emergency measures. Withdrawals were temporarily halted while the security team conducted a comprehensive audit of the withdrawal system. The platform engaged with on-chain investigators and exchange compliance teams to flag stolen funds. Skelhorn acknowledged that internal adjustments were necessary to balance user convenience with security, stating the platform would make changes to “keep the players happy but the bad actors at bay.”

The broader industry context underscores the severity of the situation. October 2024 alone saw 20 major crypto exploits totaling approximately $88.47 million in losses. Just weeks earlier, Radiant Capital suffered a $58 million breach through compromised multi-signature wallets, and the M2 exchange lost $13 million in a separate hot wallet attack.

Lessons Learned

The MetaWin incident highlights several recurring vulnerabilities in cryptocurrency platforms. First, frictionless withdrawal systems that prioritize speed over security create exploitable attack surfaces. Multi-signature wallet configurations and mandatory withdrawal delays — even brief ones — can significantly reduce the window of opportunity for attackers. Second, hot wallets should maintain minimal balances relative to total platform reserves, with the bulk of assets stored in air-gapped cold wallets. Third, real-time transaction monitoring with anomaly detection algorithms is essential for platforms handling significant user funds.

User Action Required

For MetaWin users and the broader crypto community, this incident serves as a reminder to practice vigilant security hygiene. Users should enable all available two-factor authentication methods, regularly review wallet transaction histories, and avoid keeping large balances on any single platform. Those affected by the MetaWin hack should monitor official communications from the platform and law enforcement for updates on fund recovery efforts. As the crypto industry matures, the responsibility for security is increasingly shared between platforms and their users — and the cost of getting it wrong is measured in millions.

This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult qualified professionals before making decisions about cryptocurrency security.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Inside the MetaWin Breach: How 115 Wallet Addresses Traced a 4 Million Dollar Crypto Casino Heist”

  1. CasinoExitLiquidity

    115 wallet addresses and they still couldnt stop the draining. frictionless withdrawals sound great until they frictionlessly drain your treasury

    1. hotwallet_witness

      hot wallets connected 24/7 for instant withdrawals is just asking for trouble. any crypto casino doing this in 2024 deserves what happens

      1. frictionless withdrawals optimized for speed became the attack vector. keeping hot wallets connected 24/7 for instant tx in 2024 is asking for it

      2. hot_wallet_hater_

        hotwallet_witness frictionless withdrawals and 24/7 hot wallets is the casino business model. speed is always the enemy of security. they learned that for 4 million dollars

  2. ZachXBT doing more for crypto security than every compliance team combined. tracked the funds through KuCoin and HitBTC in real time

    1. chainalysis_lol_

      zach tracked 115 wallet addresses through kucoin and hitbtc in real time. paid security teams at major exchanges missed this for months while one guy on twitter nailed it

    2. the nested service on HitBTC is classic. they always use smaller exchanges as intermediary before hitting tornado

      1. chain_sleuth hitbtc nested services have been a laundering pipeline since like 2019. regulators shut one down and three more pop up

        1. HitBTC nested services are still operating in 2024. regulators shut one down and three more appear. enforcement is always five steps behind

        2. Lena V. hitbtc nested services have been a laundering pipeline since 2019. the fact that theyre still operating tells you everything about enforcement priorities

        3. Lena V. the hitbtc nested service problem is basically whack a mole. shut one down and three pop up through different corporate structures in different jurisdictions

    3. ZachXBT_fan zach identified 115 wallet addresses and traced them through kucoin and hitbtc before any exchange flagged it. one guy on twitter outperforming entire compliance departments

      1. 115 wallet addresses and ZachXBT traced the full flow before any exchange flagged it. one guy with a twitter account outperforming Chainalysis is wild

    4. ZachXBT_fan zach tracks stuff in real time that paid security teams miss for months. the man is a one person chainalysis

      1. cex_escapee zach tracked 115 wallet addresses through KuCoin and HitBTC in real time. paid security teams at major exchanges missed this for months while one guy on twitter nailed it

  3. 4M from a casino most people never heard of. Makes you wonder how many smaller platforms are getting drained without anyone noticing.

  4. hotwallet_witness

    a crypto casino advertising frictionless withdrawals while keeping hot wallets connected 24/7 is asking for exactly this outcome. speed costs money

    1. hotwallet_witness frictionless withdrawals are a feature for users and a feature for attackers too. same infrastructure, different outcomes

      1. withdrawal_tax_ the double edged sword of frictionless withdrawals is something every casino platform faces. users demand instant but instant means no time to catch anomalies

  5. 115 wallet addresses and the funds still moved through kucoin and hitbtc without freezing. exchange compliance teams had weeks to flag this

  6. frictionless withdrawals optimized for speed became the attack vector. any platform keeping hot wallets connected 24/7 for instant tx in 2024 deserves what happens

  7. hot_wallet_grave_

    115 wallet addresses traced by ZachXBT and not a single exchange compliance team flagged the movement before he posted. one guy with a twitter account outperformed every paid security team

    1. hot_wallet_grave_ the KuCoin and HitBTC funneling path is textbook. nested services on HitBTC have been a laundering pipeline since 2019 and regulators still play whack-a-mole

  8. fault_tolerant_

    frictionless withdrawals being both the feature and the attack vector is the casino business model in a nutshell. speed is always the enemy of security

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$76,790.00-0.5%ETH$2,479.13-1.6%SOL$99.76-1.7%BNB$716.63-1.3%XRP$1.34-1.7%ADA$0.2031-1.8%DOGE$0.0825-2.5%DOT$1.00-1.7%AVAX$7.30-1.2%LINK$11.20-2.5%UNI$6.11-3.5%ATOM$1.58-1.6%LTC$53.58+0.2%ARB$0.1333-4.9%NEAR$2.30-2.0%FIL$0.9487+18.5%SUI$0.7007-3.0%BTC$76,790.00-0.5%ETH$2,479.13-1.6%SOL$99.76-1.7%BNB$716.63-1.3%XRP$1.34-1.7%ADA$0.2031-1.8%DOGE$0.0825-2.5%DOT$1.00-1.7%AVAX$7.30-1.2%LINK$11.20-2.5%UNI$6.11-3.5%ATOM$1.58-1.6%LTC$53.58+0.2%ARB$0.1333-4.9%NEAR$2.30-2.0%FIL$0.9487+18.5%SUI$0.7007-3.0%
Scroll to Top