Your Duelbits account holds cryptocurrency balances and personal information. Protecting it is your responsibility. This guide covers everything you should do to keep your account secure, how to recognise threats, and how to act fast if something goes wrong.
🔐 1: Enable Two-Factor Authentication (2FA)
This is the single most important step. With 2FA enabled, logging in requires both your password and a 6-digit code from an authenticator app on your phone. Even if someone steals your password, they cannot access your account without your device.
To enable 2FA:
Go to Profile → Security.
Under Two Factor, click Show QR.
Scan the QR code with your authenticator app (Google Authenticator, Authy, or any TOTP-compatible app).
Enter the 6-digit code and click Enable Two Factor.
Save the setup key by clicking "Copy code instead" before leaving the setup screen. This is your only self-service recovery option if you lose access to your authenticator.
Duelbits will never ask you to disable 2FA, anyone who does is not from Duelbits.
🔑 2: Use a Strong, Unique Password
Your Duelbits password must contain at least 8 characters, 1 uppercase letter, 1 special character, and 1 number. But meeting the minimum is not enough, follow these practices:
Make it unique: never reuse your Duelbits password on any other site. If another site is breached, attackers will try those credentials on crypto and gambling platforms immediately
Make it long: the longer the password, the harder it is to crack. 12+ characters is better than 8
Avoid personal information: do not use your name, birthday, username, or any word someone could guess from your social media
Use a password manager: tools like 1Password, Bitwarden, or the built-in browser manager can generate and store strong random passwords so you do not need to remember them
To change your password: Profile → Security → Change Password.
👤 3: Never Share Your Account
Per the Terms of Service (Section 4.3 and 4.4):
You are solely responsible for the security of your login credentials and 2FA
You must not allow any third party, including family members, to access your account
Duelbits is not liable for any losses resulting from unauthorised access caused by shared or unsecured credentials
This also means:
Never share your password or 2FA code with anyone, for any reason
Never log in to Duelbits on someone else's device and leave the session active
Never let someone "try a game" on your account
If another person wants to play on Duelbits, they must create their own account.
🖥️ 4: Safe Device and Browser Practices
How you use your device matters as much as your password:
Keep your browser updated: outdated browsers have known security vulnerabilities
Avoid public or shared computers: if you must use one, always log out completely when finished and do not save credentials
Avoid public Wi-Fi for gambling: open networks can be intercepted. If you must use public Wi-Fi, use a trusted VPN (but route it through your actual permitted country, not a restricted one)
Lock your phone: if your authenticator app is on your phone and your phone has no screen lock, anyone who picks it up has your 2FA codes
Be cautious with browser extensions: some extensions can read page content, including passwords and wallet addresses. Only install extensions from trusted sources and disable unnecessary ones while gambling
Bookmark duelbits.com: access the site from your bookmark rather than typing it or clicking links from search results. This eliminates the risk of landing on a lookalike phishing domain
🎣 5: Recognise Phishing Attempts
Phishing is the most common way accounts are compromised. Attackers impersonate Duelbits through fake websites, emails, and social media accounts to steal your credentials.
Duelbits will never:
Ask for your password
Ask for your 2FA code
Ask you to disable 2FA
Contact you first via Telegram, Discord, or any social media DM
Ask you to "verify" your account by clicking a link sent through social media
Red flags to watch for:
Emails from any address other than @duelbits.com (the only legitimate sender is [email protected])
Websites that look like Duelbits but have a slightly different URL (e.g., duelbitz.com, dueIbits.com, duelbits-casino.com)
Social media messages claiming you won a prize, giveaway, or bonus
Urgent or threatening language ("your account will be closed in 24 hours")
Third-party websites promising "exclusive" Duelbits promo codes in exchange for logging in
If something feels off, do not click anything. Go directly to duelbits.com by typing the URL in your browser and check your account from there.
📧 6: Pay Attention to Security Notifications
Duelbits sends account-related notifications to your registered email address, including security alerts, login confirmations, and verification requests. These emails come from [email protected].
Do not ignore unexpected security emails: if you receive a password reset email you did not request, or a notification about an action you did not take, someone may be attempting to access your account
Do not unsubscribe from transactional emails: these are required for the safe operation of your account and cannot be opted out of. Only promotional emails (MMA Jackpot, marketing) can be toggled off in Profile → Settings
🚨 7. What to Do If Your Account Is Compromised
If you suspect someone else has access to your account, or you notice activity you did not authorise, act immediately:
Step 1: Change your password right now
Go to Profile → Security → Change Password. Set a new, strong, unique password. This is the fastest way to block an attacker who has your current credentials.
Step 2: Check your 2FA
If 2FA is still enabled, the attacker likely does not have full access, they would need your authenticator device. If 2FA has been disabled without your knowledge, this is a serious compromise. Proceed to Step 3 immediately.
Step 3: Contact Duelbits support
Open the Live Support panel from the left-hand navigation bar or email [email protected]. Tell the team:
That you believe your account has been compromised
What suspicious activity you noticed (unauthorised bets, withdrawals, settings changes)
Whether your 2FA has been tampered with
The support team can investigate and take steps to secure your account.
Step 4: Review your account activity
Check your bet history and transaction history in Profile → Transactions for any activity you do not recognise. Note the dates, amounts, and types of transactions to share with the support team.
Step 5: Change passwords on other sites
If you used the same password on other websites, change it everywhere immediately. Credential stuffing attacks try leaked passwords across many platforms.
🔒 Security Checklist
Use this as a quick reference to make sure your account is properly secured:
✅ 2FA enabled with an authenticator app
✅ Setup key saved securely offline or in a password manager
✅ Strong, unique password (not reused anywhere else)
✅ Duelbits bookmarked in your browser
✅ Email verified (Profile → Verification)
✅ No one else has access to your account or credentials
✅ Phone has a screen lock enabled (protects your authenticator app)
✅ Browser and device are up to date
✅ Profile privacy enabled if you prefer hidden stats (Profile → Settings → Toggle Profile Privacy)
❓ Frequently Asked Questions
Can I lock my account instantly if I think it's compromised?
There is no self-service lock button. The fastest actions are to change your password immediately (Profile → Security) and contact support via Live Support or [email protected]. Changing your password blocks anyone using your current credentials.
Does Duelbits ever ask for my password or 2FA code?
Never. No Duelbits employee, support agent, or representative will ever ask for your password or 2FA code through any channel. Anyone who does is impersonating Duelbits.
What if I lose my phone with my authenticator app?
If you saved the setup key during 2FA configuration, enter it into a new authenticator app on another device. If you did not save it, contact [email protected] for recovery assistance.
Should I use SMS-based 2FA instead of an authenticator app?
Duelbits does not support SMS-based 2FA. Only authenticator apps are supported, which is more secure, SMS can be intercepted through SIM swapping attacks.
Can someone access my account if they know my email address?
Not without your password and 2FA code. However, knowing your email means they could attempt phishing or password reset attacks. Keep your registered email address private and monitor it for suspicious activity.