Stake Casino's Hot Wallets Drained of $41 Million Across Three Chains
Online casino Stake had more than $41 million siphoned from its hot wallets in a rapid, multi-chain breach — a reminder that in crypto, the house does not always win.
Cyvers was first to flag the unusual on-chain activity, identifying roughly $16 million in losses on Ethereum mainnet. A second wave of transfers followed shortly after, adding a further $25.6 million drained from Stake's BSC and Polygon deployments.

Rather than move quickly to confirm the incident, Stake waited close to four and a half hours — the company itself puts the figure closer to three — before issuing any public acknowledgment, a delay made more awkward by a promotional tweet the platform found time to publish in the interim.
That initial statement conspicuously omitted any mention of the Polygon-side losses and didn't address user reports that withdrawals had been frozen. Roughly four hours later, Stake posted again, telling users that deposits and withdrawals had resumed.
Co-founder Bijan Tehrani had earlier stated that customer funds would see no impact — a claim that, if accurate, only sharpens the question of why the company's public communication was so slow and so selective given the scale of the loss.
Analysis from researchers including tayvano and PeckShield reconstructed the mechanics of the theft. The first transaction went out at 12:48 UTC, and — being a simple transfer rather than any contract-level exploit — pointed to compromised private keys behind Stake's hot wallets as the likely root cause.
The haul broke down into native tokens worth roughly $14 million combined (6,000 ETH, 3 million MATIC, and 12,000 BNB), plus $22.3 million in stablecoins, $650,000 in SHIB, and $3.25 million in Binance-pegged ETH.
Stake's hot wallets on Ethereum, Polygon, and BSC went quiet roughly three hours after the draining began — consistent with the platform having genuinely suspended withdrawals over that window.
The stolen assets moved to three attacker-controlled addresses: 0x3130662aece32f05753d00a7b95c0444150bcd3c on Ethereum, 0xfe3f568d58919b14aff72bd3f14e6f55bec6c4e0 on Polygon, and 0x4464e91002c63a623a8a218bd5dd1f041b61ec04 on BSC. Non-native holdings were then swapped into native tokens and spread across further wallets — see the full breakdown and the mainnet fund-flow diagram for the complete trail.

Stake has built a large, largely mainstream user base helped by celebrity backing from Drake and relentless promotion from Bitboy — the latter, according to some commentary, also useful as a channel for laundering scam proceeds, much like a conventional casino. Rival platform Rollbit may be drawing more attention lately thanks to a rising token price, but Stake has evidently been doing just fine regardless, reportedly profitable enough for a co-founder to purchase a $28 million mansion the previous year.
That this breach landed so soon after Stake's most prominent promoter, Bitboy, fell out of the public eye struck some observers as an odd coincidence — though others noted that whoever trades shitcoins via Metamask is unlikely to be the same person capable of a multimillion-dollar heist.
Ultimately, the episode resembles many of the centralized-exchange hacks previously documented. DeFi carries a reputation for exploits of this scale, and the rekt leaderboard does little to argue otherwise — but centralized platforms arguably warrant an even higher standard. DeFi protocols expose their code and permission structures for anyone to inspect; CeFi platforms rarely disclose who holds access to the private keys guarding user funds, perhaps to avoid making individuals targets for phishing or worse. Whether that justifies leaving tens of millions of dollars behind a single set of private keys is a separate question — one worth asking again each time this kind of "coincidence" recurs.
Get new scam files the moment we publish them — usually 2–3 emails a week.