Hacks and Heists: The Security Nightmare of Crypto Betting Empires

Razed has become the latest high-profile crypto gambling site to be successfully hacked. With thousands of players logging into these sites each day, are they at risk every time they do?

Hacks and Heists: The Security Nightmare of Crypto Betting Empires

At the end of May 2026, Razed Casino, a site that had only celebrated its second year of operations the month before, went offline. Players were unable to find the site, let alone access their funds.

The reason for this soon became clear when the official account released a statement on X:

In fact, the first reassurance had come a day earlier from a member of the team, "@MarkRazed," who explained the steps to shut down the site as a "precautionary measure" to protect players' funds and assured readers, "All player funds are secure."

Players breathed a collective sigh of relief and were then able to withdraw their funds when the site came back online on June 3, albeit with their trust in the casino shaken. Nor was this Razed's only security story: in a separate incident, the site exposed 183 VIP email addresses and called it human error.

The latest in a string of exploits

Razed Casino is just the latest victim. While some may attribute this to their status as newcomers in the industry, even the biggest players are not exempt from these attacks.

In March, BC.Game lost $4.3 million after a hacker exploited a vulnerability in a third-party game that the site supported. The company has since placed a $500,000 bounty on the hacker's wallet, while on-chain analysts watched a chunk of the stolen funds disappear into leveraged bets on Hyperliquid.

The following month, a third-party games provider gave way instead of a wallet. A breach of slot maker Amatic Industries' game servers caused titles including Book of Aztec and the Lucky Joker series to pay out roughly every third spin instead of their intended rate.

Stolen Funds Chart

Stolen funds from named incidents. Source: FairGambling Research, from operator statements, the FBI and contemporaneous reporting.

The malfunction ran for around five and a half hours before Amatic patched it. Players at Slotegrator-powered, Russian-facing casinos Vodka.Bet and Vavada piled in first, with one turning a $3.50 bet into $1,200. The operators' response was inconsistent: some players kept their winnings, others got frozen or banned.

Back in November 2024, another top casino brand, MetaWin, had suffered a multi-million dollar hack. The company had previously bragged of "frictionless" withdrawals. However, this proved to be their downfall when the withdrawal system was exploited for $4 million in Ethereum and Solana. In this heist, the hackers used the cryptocurrency exchanges KuCoin and HitBTC to move stolen funds.

Perhaps the most notorious of recent crypto hacks was the one involving Stake.com in 2023. One of the biggest and most recognized brands in the crypto casino industry had at least $41 million stolen from its hot wallets, in an attack the FBI formally attributed to the infamous hacker group Lazarus.

Money isn't the only thing at risk.

In December 2025, Stake was involved in another security breach. This time, it confirmed that players' names, dates of birth, and contact details were exposed after a smishing campaign at a third-party site; Mixpanel gave attackers unauthorized access to a limited number of customer accounts on its analytics platform.

Mixpanel revoked sessions, rotated credentials, ran a company-wide password reset, brought in outside forensics, and notified affected customers directly and law enforcement, while stressing that anyone it hadn't contacted personally was not impacted.

Just a few weeks prior, Shuffle Casino, a Melbourne-based platform that processes more than $2 billion in monthly wagers, confirmed that Fast Track (a third-party CRM it used to manage customer relationships) had been attacked.

Fast Track detected the intrusion in early October, and by the time Shuffle went public on October 10, attackers had taken full names, emails, phone numbers, home addresses, transaction and support histories, betting patterns, and KYC documents including driver's licenses and passports, plus partial card data.

Fast Track's disclosure indicated two of its casino clients had been hit; Shuffle was the one to come forward publicly. Shuffle told users to turn on two-factor authentication, warned them to watch for phishing, and said it would drop Fast Track for a different CRM provider.

Bigger brands have the financial resources to absorb the hit. Stake covered the losses without touching player balances, while BC.Game has placed a bounty on the hacker behind their most recent breach.

However, these are options simply not available to smaller operators, leaving players at these sites even more vulnerable.

Timeline of Major Hacks

Twelve years apart, same root cause. Source: FairGambling Research.

The blueprint was written in 2014

The vulnerabilities go back further than many might assume. In 2014, Primedice was one of the earliest Bitcoin dice sites on the internet. It would also become one of the first documented victims of a crypto casino exploit.

A hacker, known only as "Hufflepuff", had identified a flaw in their provably fair RNG system. By flooding the server with rapid requests, he could force it into revealing active server seeds, effectively allowing him to know the outcome of each bet before placing it. The house edge became irrelevant. He simply couldn't lose.

The site's team repeatedly paid out his winnings, unable to identify any wrongdoing. By the time a developer spotted the exploit, the damage was done. When the team made contact, demanding the coins back, Hufflepuff drained what remained from the hot wallet using a workaround for the patch they had hastily applied. In total, some 2,400 BTC was lost, nearly $1 million at the time.

Contemporary forum reports suggest that Hufflepuff did not stop there. The same individual, this time operating under the username "povpobava007", is believed to have subsequently targeted Rollin.io, another early Bitcoin dice site, where a further 35 BTC was taken before the site eventually went dark. It was the same exploit, a different target, and nobody stopped him in between, though the link was never proven.

Primedice Breaking the House Article

Source: Medium

In a rare act of transparency, Primedice published a full account of the incident, including wallet addresses and IP logs. It would not be their last security headache.

In subsequent years, a withdrawal glitch was identified on the site, in which each transaction returned a small amount of Bitcoin to the sender, allowing balances to be slowly inflated through repeated micro-withdrawals. This pattern suggests the site's security problems were not a one-off, but symptomatic of the wider growing pains of an industry building itself in real time.

Primedice was not alone. From the mid-2010s, a wave of smaller exploits across early Bitcoin gambling sites, many of which never made headlines, was documented.

One user claimed on period forums to have reported a faucet exploit on 999dice in 2015, in which multiple accounts could be used to harvest and compound small payouts through the site's tip system, earning a bounty of 0.025 BTC for the disclosure. The site has since shut down.

Perhaps the most structurally significant issue flagged in this era was the double-spend vulnerability present on any site that accepts unconfirmed transactions. A player could wager, wait to see the outcome, and if they lost, attempt to reverse the transaction before it was confirmed on the blockchain. It was a known flaw, widely discussed, and not every site was in a hurry to fix it.

The vulnerabilities being discussed today are not new. They never were. This should concern new casinos and would-be players alike, because these hacks and the inherent risks they pose to players' funds are not going away. In fact, they seem to be increasing.

There are several reasons these sites are far more appealing to hackers than fiat casinos, where such attacks are virtually unheard of.

An inherent chaos

Every casino has complaints. That much is certain. A clean bill of health on a user aggregator review site or social media thread is rarer than a Mega Moolah Jackpot win. That said, the number of serious complaints regarding players' funds is disproportionate to the industry.

This raises the question of whether these illicit practices increase the likelihood that individuals will be used as cannon fodder by hacker groups. It could be that many of these vigilante groups see them as fair game.

More worryingly, though, it could indicate that the apparent behind-the-scenes chaos at crypto casinos makes them more susceptible to these attacks, as they are unable to keep their security systems up to speed with those of their fiat competitors.

It is unlikely that these sites are actively scamming customers. Holds on funds and blocked payments are widespread issues at online casinos, but there are signs that casinos might be dropping the ball on player safety.

A key factor indicating this is the lack of KYC processes at many of these casinos. Of course, anonymity is one of the guiding principles of the crypto industry, but when it comes to player safety and when so many of these casinos are under threat, it raises the question of whether these casinos know who their customers are and whether they have let a wolf into their ranks.

This links to another common complaint among crypto casino customers: that the games themselves cannot be trusted. eCOGRA is the leading independent auditor of casino games in the industry, responsible for certifying that outcomes are genuinely random and that financial flows are transparent.

However, their testing frameworks are built around fiat transactions and require players to be formally identified throughout the process. Most crypto casinos meet neither condition.

The result is that the games running on these platforms have never been independently verified, and in many cases, never will be under current frameworks.

Another issue is the promise of "provably fair". A system that is said to guarantee the fairness of games using blockchain is likely to build player trust in the absence of actual game audits. Players' belief in the system is slowly fading, with many pointing out that it only verifies the process by which a game achieves an outcome, not that the outcome itself is random.

Provably Fair

What provably fair proves, and what players assume it proves. Source: FairGambling Research.

Whole forum threads are devoted to accusing individual sites of running "fake provably fair" systems, which posters say means the games are rigged despite the system's illusion of fairness. Most of the finger-pointing isn't properly substantiated, but now and again, a provably fair break is confirmed as genuine.

Player trust in crypto casinos has been low for a long time. As far back as 2018, users were reporting suspected thefts and directly blaming casino platforms, with one CloudBet user alleging the loss of 30 BTC, a sum worth nearly $2 million today. Nothing was ever proven, and no official action was taken.

That is precisely the point. In a space with no regulator to escalate to and no paper trail to follow, allegations like this simply disappear. The hacks get the headlines. The quieter losses rarely do.

Systemic failures, structural problems

The frequency of these hacks could be a symptom of this perceived nonchalance toward player safety. But it would not be fair to lay all of this at the feet of individual operators.

Some of the issues facing these sites are inherent to the conditions surrounding cryptocurrencies and blockchain technology, and may not be fully resolved until wider adoption occurs.

Anonymity and speed

The nature of crypto makes these casinos easy prey, and the mechanics are straightforward. Transactions are fast and difficult to trace.

Once funds are gone, there is no paper trail to follow, no bank to call, and no regulator to escalate to. Crypto can be moved and transferred within minutes, meaning millions can be stolen and disappear before most operators have even identified the breach, let alone responded to it.

The Stake attack is a case in point. By the time the scale of the hot wallet drain became clear, the funds were already moving through multiple wallets and across chains.

It is worth noting that these attacks are not unique to crypto casinos. Bybit suffered one of the largest hacks in history just last year, with $1.4 billion stolen following the compromise of a third-party wallet interface. Binance, FTX, and others have all taken significant hits.

The difference is that exchanges operate under far greater regulatory scrutiny and have more robust infrastructure to respond. Crypto casinos, operating in the shadows of the industry, have neither.

Prey and tool

These casinos aren't just easy to hack. They're also handy for hiding stolen money. No KYC means nobody has to prove who they are. Fast withdrawals mean the money is gone before anyone can act. And since payouts come out of the casino's own wallet, not the player's, there's no direct link between the stolen crypto going in and the "winnings" coming out.

The trick is simple. Deposit stolen crypto, place a few bets, withdraw the winnings. On the blockchain, that money now looks clean.

Chainalysis and Elliptic, two firms that track crypto crime, have both named gambling sites as part of how stolen funds get laundered. Lazarus Group, the North Korean hackers blamed for the Stake heist, is accused of using casinos this way too: not just robbing them, but washing money through them.

So these sites end up playing two roles. Victim of one hack. Cleanup tool for another.

No license, no recourse

Credible licensing is virtually out of reach for most crypto casinos. The UKGC, the MGA, and the regulatory bodies overseeing the seven US states where online casino gambling is permitted all operate frameworks that crypto-native operators cannot realistically meet, pushing these casinos toward lighter-touch jurisdictions or no license at all. Many hold nothing whatsoever.

That matters when things go wrong. A licensed casino operating under a reputable body has institutional support, mandatory security standards, and established channels for pursuing bad actors after a breach. A crypto casino with an Anjouan license, or no license at all, has little to none of that.

Red Flags

Red flags of an unfair casino. Source: FairGambling Research.

When the money is gone, it is gone. The player has no ombudsman to call and no regulator to complain to. For some operators, this is likely intentional.

The security burden on operators

Even setting aside licensing, the technical demands of operating a crypto casino securely are considerable. Operators must distribute control over funds across multiple keys or parties, so that no single breach gives an attacker access to everything.

Wallet software needs constant maintenance, since outdated builds are among the most exploited vulnerabilities in the space. As we have seen with Stake, hot wallets are susceptible. Funds should never sit in a hot wallet; cold storage exists for a reason, and moving money into active circulation only when a transaction demands it is a basic precaution that not every operator takes seriously.

Cold vs Hot Storage

Cold storage vs hot wallet. Source: FairGambling Research.

Then there is the human element. Staff must be trained to spot phishing attempts, which remain one of the most reliable tools in a hacker's arsenal precisely because they target human error rather than code. With many of these new crypto casinos operating in a start-up environment, it is not always possible to have the right people in place to catch these threats before they land.

None of this is cutting-edge. These are table-stakes requirements, and the fact that breaches continue to occur suggests that many operators are still falling short. For players, that gap between what is required and what is actually in place represents real, tangible risk.

Where does this leave players?

The truth is, we will likely never know the true number of casino hacks and heists that have taken place over the last 12 years—since some attacks simply get swept under the rug and are never publicly announced.

If the last five years are anything to go by, and given that security systems and players' awareness of using them in the crypto space were more lackluster back then, it is likely a significant number.

What we do know is this: players do not feel safe, and quite rightfully. Whether a major powerhouse or an up-and-coming site, the risk of hacks is real, and players' faith in these sites is dwindling.

These issues are systemic in the industry, with many top sites doing little to remedy them and, in some cases, even contributing to the risk themselves. That makes mass adoption of crypto at mainstream casinos a distant prospect, if a realistic one at all. The lack of licensing, the lack of support systems, the cycle of breaches: none of it gets better on its own.

Crypto players will likely avoid excessive risk, which is set to manifest as mistrust of unknown and untested brands. Even the benefits of the bigger brands may be outweighed by the financial risks, potentially forcing players back into traditional casino models.

And if an operator has behaved badly with your funds, tell us, confidentially: documenting the quieter losses is how the pattern gets harder to ignore.

Treat gambling as entertainment you pay for. 18+, and if it stops feeling like entertainment, help exists at BeGambleAware and GamCare.

Mission Statement

Crypto gambling has a transparency problem. We're fixing it.

On-chain data and original research, not recycled press releases

Honest operator reviews and news, free from affiliate influence

Player-first reporting built on transparency and responsible gambling