Crypto casino Duel has awarded a $37,000 bug bounty through HackerOne after a researcher flagged a serious flaw in its Crash game. The vulnerability could have let a player collect winnings on a bet that had already lost.
According to a statement posted by Duel’s team on X, the exploit relied on explicit socket events, which meant the company would have been able to detect any abuse after the fact. Because the researcher who reported the issue was also the first person to discover it, Duel says no funds were actually lost before the fix went in.
Duel’s team thanked the wider community of bug bounty hunters for their role in keeping the platform secure, framing the payout as part of a broader philosophy of rewarding researchers generously in exchange for responsible disclosure.
Duel just awarded a $37,000 bug bounty to a HackerOne submission!
The H1 user disclosed a serious exploit which allowed players to receive winnings on the Crash game mode after their bet had already lost. The exploit, if abused, would have been detectable on our end as it used…
— Korra (@korraflow) August 12, 2026
Community Reaction
The announcement drew a largely positive response from Duel’s followers, with several commenters praising the company for taking security reports seriously.
Not everyone was satisfied, though. One user claimed to have separately reported a related issue – describing an incident in which three users allegedly exploited a similar flaw to generate roughly $70,000 in winnings, with about $30,000 of that later blocked from withdrawal. That user said their own report was compensated with a $250 bounty, prompting them to question the size gap between the two payouts.
Duel has not publicly responded to that specific claim.
I actually reported a bug where 3 users actually used this bug and able to rake 70k in winnings while 30k of the remaining was withdrawal blocked by duel. I got $250 for this report, this user got $37k hm ok
— Simple Math (@DEEZNUTS_URMOM1) August 13, 2026
Why It Matters
Crash-style games are popular on crypto casinos, and exploits that let users lock in guaranteed wins – or reverse losing bets – pose a direct financial risk to operators. Bug bounty programs like Duel’s are increasingly common in the industry as a way to catch these flaws before they can be exploited at scale, though payout amounts and consistency remain a point of contention among researchers, as this episode illustrates.